CVE-2018-1747XML External Entity (XXE) Injection in IBM Security KEY Lifecycle Manager

Severity
7.1HIGHNVD
EPSS
0.4%
top 42.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 15
Latest updateMay 13

Description

IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 148428.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:LExploitability: 2.8 | Impact: 4.2

Affected Packages2 packages

NVDibm/security_key_lifecycle_manager2.5.02.5.0.9+3
CVEListV5ibm/security_key_lifecycle_manager4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7gg3-qccg-9cgw: IBM Security Key Lifecycle Manager 22022-05-13
CVEList
CVE-2018-1747: IBM Security Key Lifecycle Manager 22018-10-15

💬Community

1
Bugzilla
CVE-2018-0618 mailman: Cross-site scripting vulnerability allows malicious listowners to inject scripts into listinfo pages2018-06-29
CVE-2018-1747 — XML External Entity (XXE) Injection | cvebase