Vulnerability index

Browse CVEs

127 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Security Access Manager HIGH 7.1
CVE-2019-4707

IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attac…

Mitigation only
Fix from $1,950 2020-01-28
Security Access Manager For Enterprise Single Sign On HIGH 8.2
CVE-2019-4513

IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da…

Mitigation only
Fix from $1,950 2019-08-26
Security Guardium Big Data Intelligence HIGH 8.2
CVE-2019-4340

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r…

Mitigation only
Fix from $1,950 2019-08-20
Business Automation Workflow HIGH 8.2
CVE-2019-4424

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack …

Fix: after 19.0.0.2
Fix from $1,950 2019-08-20
Infosphere Global Name Management HIGH 8.2
CVE-2019-4433

IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (…

Mitigation only
Fix from $1,950 2019-08-20
Intelligent Operations Center HIGH 8.2
CVE-2019-4419

IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 5.2.1.1
Fix from $1,950 2019-08-20
I2 Intelligent Analysis Platform HIGH 7.1
CVE-2019-4062

IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 9.1.1
Fix from $1,950 2019-07-30
Daeja Viewone HIGH 7.1
CVE-2019-4456

IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…

Fix: after 5.0.6
Fix from $1,950 2019-07-30
Infosphere Information Server HIGH 7.1
CVE-2018-1845

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remo…

Patch available
Fix from $1,950 2019-06-17
Tririga Application Platform HIGH 7.1
CVE-2019-4208

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Fix: 3.5.3.6 / 3.6.0.3+
Fix from $1,950 2019-05-07
Sterling B2b Integrator HIGH 7.1
CVE-2019-4043

IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML dat…

Fix: after 5.2.6.4
Fix from $1,950 2019-04-02
Infosphere Information Server CRITICAL 9.1
CVE-2018-1727

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A…

Mitigation only
Fix from $2,300 2019-02-15
Security Access Manager HIGH 7.1
CVE-2018-1970

IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…

Fix: after 7.0.1.10
Fix from $1,950 2019-02-04
App Connect MEDIUM 5.3
CVE-2018-1801

IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and We…

Fix: after 11.0.0.1
Fix from $1,600 2019-02-04
Security Identity Manager HIGH 7.1
CVE-2018-2019

IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot…

Patch available
Fix from $1,950 2019-01-18
Operational Decision Manager CRITICAL 9.1
CVE-2018-1821EPSS 16%

IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat…

Fix: 8.6.0.3 / 8.7.1.2+
Fix from $2,300 2018-12-13
Marketing Platform HIGH 7.1
CVE-2018-1424

IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attack…

Mitigation only
Fix from $1,950 2018-12-07
Marketing Platform HIGH 7.1
CVE-2018-1920

IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…

Mitigation only
Fix from $1,950 2018-12-07
Qradar Security Information And Event Manager HIGH 7.1
CVE-2018-1730

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t…

Fix: after 7.3.1
Fix from $1,950 2018-12-05
Websphere Application Server HIGH 7.1
CVE-2018-1905

IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 9.0.0.9
Fix from $1,950 2018-11-26
Daeja Viewone HIGH 7.1
CVE-2018-1835

IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote…

Mitigation only
Fix from $1,950 2018-11-02
Rational Engineering Lifecycle Manager HIGH 7.1
CVE-2018-1846

IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack whe…

Fix: after 6.0.6
Fix from $1,950 2018-11-02
Security Key Lifecycle Manager HIGH 7.1
CVE-2018-1747

IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A r…

Fix: after 3.0.0.1
Fix from $1,950 2018-10-15
Filenet Content Manager HIGH 7.1
CVE-2018-1844

IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…

Patch available
Fix from $1,950 2018-10-12
Platform Symphony HIGH 7.1
CVE-2018-1702

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) at…

Mitigation only
Fix from $1,950 2018-09-28
Datapower Gateway HIGH 7.1
CVE-2018-1669

IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as we…

Fix: after 7.7.1.2
Fix from $1,950 2018-09-25
Rational Engineering Lifecycle Manager HIGH 7.1
CVE-2018-1588

IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Inject…

Fix: after 6.0.6
Fix from $1,950 2018-09-25
Rational Engineering Lifecycle Manager HIGH 7.1
CVE-2018-1607

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when …

Fix: after 6.0.6
Fix from $1,950 2018-09-25
Filenet Content Manager HIGH 7.1
CVE-2018-1542

IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.…

Patch available
Fix from $1,950 2018-07-06
Rational Rhapsody Design Manager HIGH 7.1
CVE-2018-1456

IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A rem…

Patch available
Fix from $1,950 2018-06-06