1 results (0.003 seconds)

CVSS: 8.1EPSS: 0%CPEs: 2EXPL: 0

IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 204775. IBM Jazz for Service Management versión 1.1.3.10 e IBM Tivoli Netcool/OMNIbus_GUI son vulnerables a un ataque de tipo XML External Entity Injection (XXE) cuando son procesados datos XML. Un atacante remoto podría aprovechar esta vulnerabilidad para exponer información confidencial o consumir recursos de memoria. • https://exchange.xforce.ibmcloud.com/vulnerabilities/204775 https://www.ibm.com/support/pages/node/6490905 • CWE-611: Improper Restriction of XML External Entity Reference •