SB2026091617 - XML external entity injection in IBM Cloud Pak for Applications



SB2026091617 - XML external entity injection in IBM Cloud Pak for Applications

Published: September 16, 2026

Security Bulletin ID SB2026091617
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) XML External Entity injection (CVE-ID: CVE-2026-65432)

CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper restriction of XML external entity references in WSDL4J import parsing when processing imported WSDL or XSD documents referenced by a top-level WSDL. A remote attacker can supply a specially crafted imported WSDL or XSD document to disclose sensitive information.

The issue affects imported documents referenced through <wsdl:import> or <xsd:import>, while the top-level WSDL is processed through a hardened parsing path.


Remediation

Install update from vendor's website.