PT-2018-14416 · Ibm · Daeja Viewone Virtual+2
Published
2018-11-02
·
Updated
2019-10-09
·
CVE-2018-1835
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
IBM Daeja ViewONE Professional, Standard & Virtual version 5
Description
The issue allows a remote attacker to expose sensitive information or consume memory resources through a XML External Entity Injection (XXE) attack when processing XML data.
Recommendations
For IBM Daeja ViewONE Professional, Standard & Virtual version 5, update to a version that fixes this issue, as the current version is susceptible to XML External Entity Injection attacks.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Daeja Viewone Professional
Daeja Viewone Standard
Daeja Viewone Virtual