IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.
2023-10-14T15:15:09.643
2024-11-21T07:06:53.963
Modified
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | security_directory_server | 6.4.0.0 | Yes |
Application | ibm | security_directory_suite | 8.0.1 | Yes |
Application | ibm | security_verify_directory | 10.0.0 | Yes |