XML injection in IBM AIX - CVE-2017-1289

 

XML injection in IBM AIX - CVE-2017-1289

Published: May 24, 2017 / Updated: June 27, 2017


Vulnerability identifier: #VU6667
CSH Severity: Low
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1289
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform XXE attack.

The weakness exists due to improper handling of XML External Entity (XXE) entries when parsing an XML data. A remote attacker can supply a specially crafted XML file to disclose important data or consume memory resources.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

IBM AIX
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
SUSE Linux
Red Hat Satellite

How to mitigate CVE-2017-1289

Install update from vendor's website.


External References

Related Security Bulletins