XML External Entity injection in expat - CVE-2024-28757
Published: March 11, 2024 / Updated: May 21, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input when using external parsers via XML_ExternalEntityParserCreate. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
Oracle Linux
Oracle Solaris
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
OpenBSD
IBM AIX
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Cognos Dashboards on Cloud Pak for Data
Financial Transaction Manager for RedHat OpenShift
Tivoli Network Manager IP Edition
Db2 Big SQL
IBM OpenPages with Watson
Datacap
CICS Transaction Gateway for Multiplatforms
IBM OS Image for Red Hat Linux Systems
Storage Resource Manager
Storage Protect Server
Integrated System for Microsoft Azure Stack Hub
OpenShift API for Data Protection (OADP)
IBM Security Guardium Key Lifecycle Manager (GKLM)
WebSphere Remote Server
IBM Security Verify Governance
Run Once Duration Override Operator for Red Hat OpenShift
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Kube Descheduler Operator for Red Hat OpenShift
App Connect Enterprise Certified Container
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Cloud Pak for Business Automation
IBM Observability with Instana
IBM VIOS
iDRAC9
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
expat-debuginfo
expat
expat-debugsource
expat-devel
expat-help
libexpat1-64bit
libexpat1-32bit-debuginfo
libexpat-devel-32bit
expat-32bit-debuginfo
libexpat1-32bit
expat-64bit-debuginfo
libexpat-devel-64bit
libexpat1
libexpat1-debuginfo
libexpat-devel
libexpat1-64bit-debuginfo
libexpat1 (Ubuntu package)
expat (Ubuntu package)
expat (Red Hat package)
expat-static
expat-doc
mingw-expat
python3.8
python3
python3.9
python3.10
BIG-IP
PowerScale OneFS
HPE NonStop Virtual Tape Repository (VTR)
Red Hat OpenShift Serverless
IBM Cloud Pak System
Red Hat OpenShift Container Platform
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
IBM DB2
IBM CICS TX Standard
How to mitigate CVE-2024-28757
Oracle Solaris - update to 11.4 SRU 71
OpenShift API for Data Protection (OADP) - update to 1.3.1
Tivoli Network Manager IP Edition - update to 4.2.0.20
iDRAC9 - addressed in versions 7.00.00.184, 7.30.30.51
Db2 Big SQL - update to 7.6.8
BIG-IP - update to 17.1.2.2
HPE NonStop Virtual Tape Repository (VTR) - update to T09644V01^AAK
Red Hat OpenShift Serverless - update to 1
Run Once Duration Override Operator for Red Hat OpenShift - addressed in versions 1.1.2, 1.2.0
expat-debuginfo - update to 2.2.9-11
expat - update to 2.2.9-11
expat-debugsource - update to 2.2.9-11
expat-devel - update to 2.2.9-11
expat-help - update to 2.2.9-11
IBM Cloud Pak System - update to 2.3.4.1
libexpat1-64bit - update to 2.4.4-150400.3.17.1
libexpat1-32bit-debuginfo - update to 2.4.4-150400.3.17.1
libexpat-devel-32bit - update to 2.4.4-150400.3.17.1
expat-32bit-debuginfo - update to 2.4.4-150400.3.17.1
libexpat1-32bit - update to 2.4.4-150400.3.17.1
expat-64bit-debuginfo - update to 2.4.4-150400.3.17.1
libexpat-devel-64bit - update to 2.4.4-150400.3.17.1
libexpat1 - update to 2.4.4-150400.3.17.1
expat - update to 2.4.4-150400.3.17.1
libexpat1-debuginfo - update to 2.4.4-150400.3.17.1
expat-debugsource - update to 2.4.4-150400.3.17.1
expat-debuginfo - update to 2.4.4-150400.3.17.1
libexpat-devel - update to 2.4.4-150400.3.17.1
libexpat1-64bit-debuginfo - update to 2.4.4-150400.3.17.1
libexpat1 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu0.3, 2.5.0-2ubuntu0.1
expat (Ubuntu package) - addressed in versions 2.4.7-1ubuntu0.3, 2.5.0-2ubuntu0.1
expat - update to 2.5.0-1
expat (Red Hat package) - addressed in versions 2.5.0-1.el9_2.1, 2.5.0-1.el9_3.1
expat-static - update to 2.5.0-4
expat-devel - update to 2.5.0-4
expat - update to 2.5.0-4
expat-doc - update to 2.5.0-4
mingw-expat - addressed in versions 2.6.1-1.fc38, 2.6.1-1.fc39, 2.6.1-1.fc40
expat - update to 2.6.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.10.4
python3.8 - addressed in versions 3.8.20-1.fc39, 3.8.20-1.fc40, 3.8.20-1.fc41
python3 - update to 3.9.20
python3.9 - addressed in versions 3.9.20-1.fc39, 3.9.20-1.fc40, 3.9.20-1.fc41
IBM Cloud Transformation Advisor - update to 3.10.0
python3.10 - addressed in versions 3.10.15-1.fc39, 3.10.15-1.fc40, 3.10.15-1.fc41
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM OS Image for Red Hat Linux Systems - update to 4.0.4.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Red Hat OpenShift Container Platform - addressed in versions 4.12.60, 4.13.45, 4.13.65, 4.14.31, 4.14.63, 4.15.19, 4.15.62, 4.16.0, 4.16.1, 4.16.58, 4.17.51, 4.18.35, 4.19.28
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Storage Resource Manager - update to 5.0.1.0
Kube Descheduler Operator for Red Hat OpenShift - addressed in versions 5.0.2, 5.1.0
App Connect Enterprise Certified Container - addressed in versions 5.0.17, 11.5.0
IBM Tivoli Business Service Manager - update to 6.2.0.5.5
Dell EMC VxRail Appliance - update to 8.0.212
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.4
Storage Protect Server - update to 8.1.24
PowerScale OneFS - addressed in versions 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0
IBM DB2 - addressed in versions 10.5 FP11, 11.1.4.7
IBM CICS TX Standard - update to 11.1.0.0 ifix40
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
IBM Observability with Instana - update to 272
Integrated System for Microsoft Azure Stack Hub - update to 2606
External References
Related Security Bulletins
- XXE in libexpat
- Fedora 39 update for mingw-expat
- Fedora 40 update for mingw-expat
- Fedora 38 update for mingw-expat
- Slackware Linux update for expat
- Ubuntu update for expat
- OpenBSD update for libexpat
- Red Hat Enterprise Linux 9 update for expat
- SUSE update for expat
- openEuler update for expat
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat Ceph Storage 6.1
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Red Hat Enterprise Linux 9.2 Extended Update Support update for expat
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- XML external entity injection in IBM Db2 NSE (Net Search Extender)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- XML external entity injection in IBM AIX and IBM VIOS
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM Cloud APM
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Amazon Linux AMI update for expat
- Multiple vulnerabilities in IBM OpenPages with Watson
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in Datacap
- Oracle Solaris update for thrid-party components
- Slackware Linux update for python3
- Fedora 41 update for python3.10
- Fedora 40 update for python3.10
- Fedora 39 update for python3.10
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- Fedora 41 update for python3.9
- Fedora 40 update for python3.9
- Fedora 39 update for python3.9
- Fedora 39 update for python3.8
- Fedora 41 update for python3.8
- Fedora 40 update for python3.8
- Multiple vulnerabilities in HPE NonStop Vrtual Tape Repository (VTR)
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift 1.2
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in Kube Descheduler Operator for Red Hat OpenShift 5.1
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift 1.1
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition (ITNM)
- Multiple vulnerabilities in Kube Descheduler Operator for Red Hat OpenShift 5.0
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- F5 BIG-IP iControl update for expat
- Anolis OS update for expat
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in IBM Big SQL on IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Financial Transaction Manager (FTM) for RedHat OpenShift
- XML External Entity injection in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- XML External Entity injection in Red Hat OpenShift Container Platform 4.17
- XML External Entity injection in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Dell iDRAC9
- Multiple vulnerabilities in Dell Integrated System for Microsoft Azure Stack Hub 14G and 16G