CVE-2018-1801

MEDIUM

IBM App Connect 11.0.0.0 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to consume memory resources. IBM X-Force ID: 149639.

References (2)

Core 2
Core References
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/149639
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ibm10795780

Scores

CVSS v3 5.3
EPSS 0.0245
EPSS Percentile 82.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-611
Status published
Products (3)
ibm/app_connect 11.0.0.0 - 11.0.0.1
ibm/integration_bus 9.0.0.0 - 9.0.0.10
ibm/websphere_message_broker 8.0.0.0 - 8.0.0.9
Published Feb 04, 2019
Tracked Since Feb 18, 2026