Record summary

CVE-2018-1821 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.

Description

IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150170.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Operational Decision Management

Browse IBM / Operational Decision Management
CVE List8.5affected
8.6affected
8.7affected
8.8affected
8.9affected

Proofs of concept

1

Catalogued exploits

ExploitDBIBM Operational Decision Manager 8.x - XML External Entity InjectionExploitDB exploitby Mohamed M.FouadNot analyzed1 file
ExploitDB

PoC details

References

5