CVE-2023-32327

HIGH

IBM Security Verify Access 10.0.0.0-10.0.6.1 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 254783.

References (3)

Core 3
Core References
Patch, Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7106586

Scores

CVSS v3 7.1
EPSS 0.0096
EPSS Percentile 56.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (2)
ibm/security_verify_access 10.0.0.0 - 10.0.6.1
ibm/security_verify_access_docker 10.0.0.0 - 10.0.6.1
Published Feb 03, 2024
Tracked Since Feb 18, 2026