CVE-2024-27266

Severity
8.2HIGH
EPSS
0.0%
top 92.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14

Description

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 284566.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:LExploitability: 3.9 | Impact: 4.2

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
CVEList
IBM Maximo Application Suite XML external entity injection2024-03-14
GHSA
GHSA-rfrv-rc39-gxfp: IBM Maximo Application Suite 72024-03-14
CVE-2024-27266 (HIGH CVSS 8.2) | IBM Maximo Application Suite 7.6.1. | cvebase.io