Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
10.5
affected
10.7
affected
10.11
affected
10.15
affected
Description
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.
Problem types
CWE-611 Improper Restriction of XML External Entity Reference
Product status
10.5
10.7
10.11
10.15
Credits
Filip Dragovic
References
www.ibm.com/support/pages/node/7237146