cbcvebase.
CVE-2019-4707
published 2020-01-28

CVE-2019-4707: IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could…

high7.1CVSS 3.1
AVNACLPRLUINSUCHINAL
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmsecurity_access_manager
ibmsecurity_access_manager_appliance