CVE-2019-4433
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Exploitability: 3.9 / Impact: 4.2
Source: NVD
Description
IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162890.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0 | |
| Version 8.1 |
References (6)
Source: psirt@us.ibm.com
Broken LinkVDB Entry
Source: psirt@us.ibm.com
MitigationVendor Advisory
Source: psirt@us.ibm.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.