Back to search
CVE-2017-1289
Published: May 22, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.
| Vendor | Product | Versions |
|---|---|---|
IBM Corporation | Runtimes for Java Technology | affected 6.0, 6.1, 7.0, 7.1, 8.0 |
References
RHSA-2017:1221
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1220
vendor-advisory
x_refsource_REDHAT
https://www.ibm.com/support/docview.wss?uid=swg22002169
x_refsource_CONFIRM
RHSA-2017:1222
vendor-advisory
x_refsource_REDHAT
98401
vdb-entry
x_refsource_BID
RHSA-2017:3453
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now