High Severity

IBM Security Bulletin: IBM InfoSphere Information Server is potentially vulnerable to XML External Entity Injection (XXE)

Share this post:

An XML External Entity Injection (XXE) vulnerability in InfoSphere Information Server Manager can potentially be used by an attacker to retrieve sensitive documents. Information Server Manager has a bulk import feature to help users import lists of Source Control Module (SCM) websites or user names. Use case examples for the bulk load feature are: – Multiple users want to use the SCM and there are three or more sites that need to be added. – DataStage version upgrades (i.e. version 11.3 to version 11.5) IBM Information Server Manager uses XML format for export and import of the SCM web site name and the links. Information Server Manager also allows the same information to be keyed in manually into the Add Available Software Sites dialog. There is a potential vulnerability when importing the website list using XML import.

CVE(s): CVE-2018-1727

Affected product(s) and affected version(s):

The following products, running on all supported platforms, are affected:
IBM InfoSphere Information Server: versions 9.1, 11.3, 11.5, and 11.7
IBM InfoSphere Information Server on Cloud: versions 11.5, and 11.7

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10718887
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/147630

More stories

IBM Security Bulletin: Vyatta 5600 vRouter Software Patches – Release 1801-v

Apr 20, 2019 9:00 am EDT | High Severity

AT&T has released version 1801-v for the Vyatta 5600. Details of this release can be found at https://cloud.ibm.com/docs/infrastructure/virtual-router-appliance?topic=virtual-router-appliance-at-t-vyatta-5600-vrouter-software-patches#at-t-vyatta-5600-vrouter-software-patches CVE(s): CVE-2018-8905, CVE-2018-7456, CVE-2018-5784, CVE-2018-18557, CVE-2018-1710, CVE-2018-16335, CVE-2018-15209, CVE-2018-10963, CVE-2017-17095, CVE-2017-11613, CVE-2018-19788, CVE-2018-19628, CVE-2018-19627, CVE-2018-18226, CVE-2018-18225, CVE-2018-12086, CVE-2018-16866, CVE-2018-16865, CVE-2018-16864, CVE-2019-6250, CVE-2018-19967, CVE-2018-19965, CVE-2018-19962, CVE-2018-19961, CVE-2019-3462, CVE-2018-0737, CVE-2018-0735, CVE-2018-0734, CVE-2018-0732, CVE-2018-5407, CVE-2018-19966 Affected product(s) and affected version(s):VRA ...read more


IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Cognos TM1 (CVE-2018-3180, CVE-2018-12547)

Apr 19, 2019 9:00 am EDT | High Severity

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 7 used by IBM Cognos TM1. These issues were disclosed as part of the IBM Java SDK updates in October 2018 and January 2019. CVE(s): CVE-2018-3180, CVE-2018-12547 Affected product(s) and affected version(s): IBM Cognos TM1 10.2.2 Refer to the following reference URLs for remediation and ...read more


IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Cognos Insight (CVE-2018-3180, CVE-2018-12547)

Apr 19, 2019 9:00 am EDT | High Severity

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 7 used by IBM Cognos Insight. These issues were disclosed as part of the IBM Java SDK updates in October 2018 and January 2019. CVE(s): CVE-2018-3180, CVE-2018-12547 Affected product(s) and affected version(s): IBM Cognos Insight 10.2.2 Refer to the following reference URLs for remediation and ...read more