CVE-2018-1801
published 2019-02-04CVE-2018-1801: IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere…
PriorityP430medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
2.45%
82.5th percentile
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to consume memory resources. IBM X-Force ID: 149639.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | app_connect | — | — |
| ibm | app_connect | — | — |
| ibm | app_connect | 11.0.0.0 – 11.0.0.1 | — |
| ibm | integration_bus | — | — |
| ibm | integration_bus | — | — |
| ibm | integration_bus | — | — |
| ibm | integration_bus | — | — |
| ibm | integration_bus | 10.0.0.0 – 10.0.0.13 | — |
| ibm | integration_bus | 9.0.0.0 – 9.0.0.10 | — |
| ibm | websphere_message_broker | — | — |
| ibm | websphere_message_broker | — | — |
| ibm | websphere_message_broker | 8.0.0.0 – 8.0.0.9 | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6978-8w7h-mg7h: IBM App Connect V11
ghsa_unreviewed·2022-05-13
CVE-2018-1801 [MEDIUM] CWE-611 GHSA-6978-8w7h-mg7h: IBM App Connect V11
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to consume memory resources. IBM X-Force ID: 149639.
CISA
GIGABYTE Multiple Products Code Execution Vulnerability
cisa·2022-10-24·CVSS 7.8
CVE-2018-19322 [HIGH] CWE-749 GIGABYTE Multiple Products Code Execution Vulnerability
Vulnerability: GIGABYTE Multiple Products Code Execution Vulnerability
Affected: GIGABYTE Multiple Products
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19322
Remediation Due Date: 2022-11-14
CISA
GIGABYTE Multiple Products Unspecified Vulnerability
cisa·2022-10-24·CVSS 7.8
CVE-2018-19320 [HIGH] GIGABYTE Multiple Products Unspecified Vulnerability
Vulnerability: GIGABYTE Multiple Products Unspecified Vulnerability
Affected: GIGABYTE Multiple Products
The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.
Required Action: Apply updates per vendor instructions.
Notes: https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19320
Remediation Due Date: 2022-11-14
CISA
GIGABYTE Multiple Products Privilege Escalation Vulnerability
cisa·2022-10-24·CVSS 9.8
CVE-2018-19323 [CRITICAL] GIGABYTE Multiple Products Privilege Escalation Vulnerability
Vulnerability: GIGABYTE Multiple Products Privilege Escalation Vulnerability
Affected: GIGABYTE Multiple Products
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19323
Remediation Due Date: 2022-11-14
CISA
GIGABYTE Multiple Products Privilege Escalation Vulnerability
cisa·2022-10-24·CVSS 7.8
CVE-2018-19321 [HIGH] GIGABYTE Multiple Products Privilege Escalation Vulnerability
Vulnerability: GIGABYTE Multiple Products Privilege Escalation Vulnerability
Affected: GIGABYTE Multiple Products
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19321
Remediation Due Date: 2022-11-14
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-02-04
Published