XXE attack in IBM WebSphere Application Server - CVE-2018-1905
Published: November 20, 2018 / Updated: November 29, 2018
Vulnerability details
The vulnerability exists due to improper handling of XML External Entities (XXEs) when parsing an XML file. A remote attacker can trick the victim into open an XML file that submits malicious input and obtain potentially sensitive information or consume excessive resources to cause the server to crash.