#VU34847 XML External Entity injection in IBM Security Verify Access - CVE-2019-4707
Published: January 28, 2020 / Updated: August 8, 2020
IBM Security Verify Access
IBM Corporation
Description
The vulnerability allows a remote authenticated user to #BASIC_IMPACT#.
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.