CVE-2017-1289
Summary
| CVE | CVE-2017-1289 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-22 20:29:00 UTC |
| Updated | 2018-01-05 02:31:00 UTC |
| Description | IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Ibm |
Sdk |
All |
service_refresh_16_fp41 |
All |
All |
| Application |
Ibm |
Sdk |
All |
service_refresh_8_fp41 |
All |
All |
| Application |
Ibm |
Sdk |
All |
service_refresh_10_fp1 |
All |
All |
| Application |
Ibm |
Sdk |
All |
service_refresh_4_fp1 |
All |
All |
| Application |
Ibm |
Sdk |
All |
service_refresh_4_fp2 |
All |
All |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376056 IBM Cognos Analytics Multiple Vulnerabilities (566643)