PT-2024-10052 · Ibm · Ibm Websphere Application Server Liberty+1
Published
2024-04-16
·
Updated
2024-07-03
·
CVE-2024-22354
CVSS v3.1
7.0
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server versions 8.5, 9.0
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 24.0.0.5
Description
The issue is related to incorrect restriction of XML links to external objects, which can be exploited by a remote attacker to expose sensitive information, consume memory resources, or conduct a server-side request forgery attack when processing XML data.
Recommendations
For IBM WebSphere Application Server versions 8.5, 9.0, update to a version that includes the fix for this issue.
For IBM WebSphere Application Server Liberty versions 17.0.0.3 through 24.0.0.5, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting the processing of XML data to minimize the risk of exploitation.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Websphere Application Server
Ibm Websphere Application Server Liberty