CVE-2017-1219XML External Entity (XXE) Injection in IBM Bigfix Family

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 32.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateMay 17

Description

IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 123859.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:HExploitability: 1.2 | Impact: 5.2

Affected Packages2 packages

CVEListV5ibm/bigfix_family9.1, 9.2+1
NVDibm/bigfix_platform15 versions+14

🔴Vulnerability Details

3
GHSA
GHSA-mhpc-25wr-qcwq: IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data2022-05-17
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities2018-02-22
CVEList
CVE-2017-1219: IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data2017-07-19

💥Exploits & PoCs

1
Exploit-DB
Apple macOS - Lack of Bounds Checking in HIServices Custom CFObject Serialization Local Privilege Escalation2017-05-23
CVE-2017-1219 — XML External Entity (XXE) Injection | cvebase