An XML External Entity Injection (XXE) vulnerability in InfoSphere Information Server Manager can potentially be used by an attacker to retrieve sensitive documents. Information Server Manager has a bulk import feature to help users import lists of Source Control Module (SCM) websites or user names. Use case examples for the bulk load feature are: – Multiple users want to use the SCM and there are three or more sites that need to be added. – DataStage version upgrades (i.e. version 11.3 to version 11.5) IBM Information Server Manager uses XML format for export and import of the SCM web site name and the links. Information Server Manager also allows the same information to be keyed in manually into the Add Available Software Sites dialog. There is a potential vulnerability when importing the website list using XML import.
CVE(s): CVE-2018-1727
Affected product(s) and affected version(s):
The following products, running on all supported platforms, are affected:
IBM InfoSphere Information Server: versions 9.1, 11.3, 11.5, and 11.7
IBM InfoSphere Information Server on Cloud: versions 11.5, and 11.7
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10718887
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/147630
The post IBM Security Bulletin: IBM InfoSphere Information Server is potentially vulnerable to XML External Entity Injection (XXE) appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ibm.co/2SGuSsM
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.