CVE Vulnerabilities

CVE-2024-22354

Improper Restriction of XML External Entity Reference

Published: Apr 17, 2024 | Modified: Mar 06, 2025
CVSS 3.x
7
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forgery attack. IBM X-Force ID: 280401.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Websphere_application_server Ibm 8.5.0.0 (including) 8.5.5.26 (excluding)
Websphere_application_server Ibm 9.0.0.0 (including) 9.0.5.20 (excluding)
Websphere_application_server Ibm 17.0.0.3 (including) 24.0.0.6 (excluding)

Potential Mitigations

References