CVE-2024-22354

HIGH

IBM WebSphere Application Server <24.0.0.5 - XXE

Title source: llm
STIX 2.1

Description

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forgery attack. IBM X-Force ID: 280401.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7148426
Third Party Advisory, VDB Entry vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/280401

Scores

CVSS v3 7.0
EPSS 0.0065
EPSS Percentile 46.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (2)
ibm/websphere_application_server 17.0.0.3 - 24.0.0.6
ibm/websphere_application_server 8.5.0.0 - 8.5.5.26
Published Apr 17, 2024
Tracked Since Feb 18, 2026