XML External Entity injection in IBM WebSphere Application Server - CVE-2023-27554
Published: May 11, 2023
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote user can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
IBM Workload Scheduler
IBM Operations Analytics Predictive Insights
WebSphere Remote Server
IBM Business Automation Workflow
IBM Intelligent Operations Center
IBM Tivoli Monitoring
IBM Security Verify Governance
How to mitigate CVE-2023-27554
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Security Verify Governance - update to 10.0.1.0.5
External References
Related Security Bulletins
- XXE in IBM WebSphere Application Server
- XXE in IBM Business Automation Workflow
- XXE in IBM WebSphere Remote Server
- XML external entity injection in IBM Intelligent Operations Center
- Multiple vulnerabilities in IBM Security Verify Governance
- IBM Operations Analytics Predictive Insights update for IBM WebSphere Application Server
- Multiple vulnerabilities in IBM Tivoli Monitoring
- XML External Entity injection in IBM Workload Scheduler