ibm app-connect CVE-2018-1801 vulnerability in IBM Products
Published on February 4, 2019

IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to consume memory resources. IBM X-Force ID: 149639.

NVD


Products Associated with CVE-2018-1801

Want to know whenever a new CVE is published for IBM products? stack.watch will email you.

 
 
 

Affected Versions

IBM Integration Bus: IBM WebSphere Message Broker: IBM App Connect:

Exploit Probability

EPSS
0.28%
Percentile
50.69%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.