106325vdb entry
http://www.securityfocus.com/bid/106325 CVE-2018-1821
HIGH
IBM Operational Decision Manager 8.x - XML External Entity Injection
Record summary
CVE-2018-1821 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150170.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Operational Decision ManagementBrowse IBM / Operational Decision Management | CVE List | 8.5 | affected |
| 8.6 | affected | ||
| 8.7 | affected | ||
| 8.8 | affected | ||
| 8.9 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBIBM Operational Decision Manager 8.x - XML External Entity InjectionExploitDB exploitby Mohamed M.FouadNot analyzed1 file
References
5ibm-websphere-cve20181821-xxe(150170)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/150170 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-1821 46017exploit
https://www.exploit-db.com/exploits/46017 ibm.comConfirmation
https://www.ibm.com/support/docview.wss?uid=ibm10744149