CVE-2018-1364XML External Entity (XXE) Injection in IBM Content Navigator

Severity
8.2HIGHNVD
EPSS
0.5%
top 32.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 29
Latest updateMay 14

Description

IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 137449.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:LExploitability: 3.9 | Impact: 4.2

Affected Packages2 packages

CVEListV5ibm/content_navigator5 versions+4
NVDibm/content_navigator2.0.3, 3.0.2, 3.0.3+2

🔴Vulnerability Details

2
GHSA
GHSA-9w5q-vv7j-283j: IBM Content Navigator 22022-05-14
CVEList
CVE-2018-1364: IBM Content Navigator 22018-01-29

💬Community

2
Bugzilla
CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c2018-09-06
Bugzilla
CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch2018-03-23
CVE-2018-1364 — XML External Entity (XXE) Injection | cvebase