HIGH
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data
Published Sep 25, 2018
7.1
HIGHCVSS 3.0
EPSS 1.85%
Description
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 143501.
Affected products
-
- Version 5.0StatusaffectedConstraints-
- Version 5.01StatusaffectedConstraints-
- Version 5.02StatusaffectedConstraints-
- Version 6.0StatusaffectedConstraints-
- Version 6.0.1StatusaffectedConstraints-
- Version 6.0.2StatusaffectedConstraints-
- Version 6.0.3StatusaffectedConstraints-
- Version 6.0.4StatusaffectedConstraints-
- Version 6.0.5StatusaffectedConstraints-
- Version 6.0.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | Rational Engineering Lifecycle Manager | n/a |
|
OR
- ≥ 5.0 · ≤ 5.0.2
- ≥ 6.0 · ≤ 6.0.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-12167 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/143501 vdb-entryx_refsource_XFVDB EntryVendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10731511 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-12167 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/143501 | vdb-entryx_refsource_XFVDB EntryVendor Advisory | |
| https://www.ibm.com/support/docview.wss?uid=ibm10731511 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Sep 25, 2018
Updated Sep 16, 2024
Reserved Dec 13, 2017
Link CVE-2018-1588
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-12167 Assigner ibm
Published Sep 25, 2018
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2018-12167