QID 378508

Date Published: 2023-06-05

QID 378508: IBM WebSphere Application Server is vulnerable to an XML External Entity (XXE) Injection vulnerability

IBM WebSphere Application Server is vulnerable to an XML External Entity (XXE) Injection vulnerability.

Affected Versions:
WebSphere Application Server Version 9.0.0.0 through 9.0.5.15
WebSphere Application Server Version 8.5.0.0 through 8.5.5.23

QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version and also checks for fix pack version.

This vulnerability allow a remote attacker to exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to minimal fix pack levels6989451 or Apply Fix Pack 9.0.5.16 or later for 9.0 versions and 8.5.5.24 or later for 8.5 versions.
    Vendor References

    CVEs related to QID 378508

    Software Advisories
    Advisory ID Software Component Link
    6989451 URL Logo www.ibm.com/support/pages/node/6989451