CVE-2017-1219
published 2017-07-19CVE-2017-1219: IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…
PriorityP338medium6.5CVSS 3.0
AVNACLPRHUINSUCHINAH
EPSS
2.08%
79.4th percentile
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 123859.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | bigfix_family | — | — |
| ibm | bigfix_family | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| linux | linux_kernel | >= 0 < 4.4.0-116.140 | 4.4.0-116.140 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mhpc-25wr-qcwq: IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data
ghsa_unreviewed·2022-05-17
CVE-2017-1219 [MEDIUM] CWE-611 GHSA-mhpc-25wr-qcwq: IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 123859.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-02-22·CVSS 5.5
CVE-2017-17712 linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel
did not properly track reference counts when merging buffers. A local
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2017-1219
No detection rules found.
No writeups or analysis indexed.
2017-07-19
Published