CVE-2018-1801 vulnerability in IBM Products
Published on February 4, 2019
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to consume memory resources. IBM X-Force ID: 149639.
Products Associated with CVE-2018-1801
Want to know whenever a new CVE is published for IBM products? stack.watch will email you.
Affected Versions
IBM Integration Bus:- Version 9.0.0.0 is affected.
- Version 10.0.0.0 is affected.
- Version 9.0.0.10 is affected.
- Version 10.0.0.13 is affected.
- Version 8.0.0.0 is affected.
- Version 8.0.0.9 is affected.
- Version 11.0.0.0 is affected.
- Version 11.0.0.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.