SB2022110412 - XXE attack in IBM Security Verify Governance
Published: November 4, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) XXE attack (CVE-ID: CVE-2018-1000632)
The vulnerability allows a remote attacker to conduct XXE attack on the target system.
The vulnerability exists due to improper sanitization of elements and attribute names in XML documents. A remote attacker can trick the victim into opening a specially crafted XML document that submits malicious input, perform XXE attack and bypass security restrictions to access and modify sensitive information on the system.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-verify-governance-is-vulnerable-to-arbitrary-code-execution-due-to-use-of-dom4j-cve-2018-1000632/"
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-verify-governance-is-vulnerable-to-arbitrary-code-execution-due-to-use-of-dom4j-cve-2018-1000632/</a><br>
- https://www.ibm.com/support/pages/node/6836923<br><br></p>