IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
History

Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Feb 2025 20:45:00 +0000

Type Values Removed Values Added
Description IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Title IBM EntireX XML external entity injection
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-02-06T20:29:04.129Z

Updated: 2025-02-22T22:11:33.331Z

Reserved: 2024-11-30T14:47:41.352Z

Link: CVE-2024-54171

cve-icon Vulnrichment

Updated: 2025-02-12T19:41:01.497Z

cve-icon NVD

Status : Received

Published: 2025-02-06T21:15:21.453

Modified: 2025-02-06T21:15:21.453

Link: CVE-2024-54171

cve-icon Redhat

No data.