ZeroHour

CVE-2024-54171

CVSS 3.1
7.1 high
EPSS
<1%p31
Published
()
Modified
Description

IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Vendors
ibm
Products
entirex
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.