IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
2024-11-04T20:15:05.013
2024-11-06T23:04:04.673
Analyzed
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | websphere_application_server | < 8.5.5.27 | Yes |
Application | ibm | websphere_application_server | < 9.0.5.22 | Yes |