CVE-2017-1289
published 2017-05-22CVE-2017-1289: IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this…
PriorityP347high8.2CVSS 3.0
AVNACLPRNUINSUCHINAL
EPSS
3.63%
88.3th percentile
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sdk | <= 6 | — |
| ibm | sdk | <= 6r1 | — |
| ibm | sdk | <= 7 | — |
| ibm | sdk | <= 7r1 | — |
| ibm | sdk | <= 8 | — |
| ibm_corporation | runtimes_for_java_technology | — | — |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: XML External Entity Injection (XXE) error when processing XML data
vendor_redhat·2017-05-09·CVSS 8.2
CVE-2017-1289 [HIGH] CWE-611 JDK: XML External Entity Injection (XXE) error when processing XML data
JDK: XML External Entity Injection (XXE) error when processing XML data
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.
GHSA
GHSA-xf3v-qxxv-424v: IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data
ghsa_unreviewed·2022-05-14
CVE-2017-1289 [HIGH] CWE-611 GHSA-xf3v-qxxv-424v: IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.
No detection rules found.
http://www.securityfocus.com/bid/98401https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:3453https://www.ibm.com/support/docview.wss?uid=swg22002169http://www.securityfocus.com/bid/98401https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:3453https://www.ibm.com/support/docview.wss?uid=swg22002169
2017-05-22
Published