CVE Database
/

CVE-2017-1289

Back to search

CVE-2017-1289

Published: May 22, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.

VendorProductVersions

IBM Corporation

Runtimes for Java Technology

affected
6.0, 6.1, 7.0, 7.1, 8.0

References

RHSA-2017:1221
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1220
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1222
vendor-advisory
x_refsource_REDHAT
98401
vdb-entry
x_refsource_BID
RHSA-2017:3453
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now