High Severity

IBM Security Bulletin: IBM InfoSphere Information Server is potentially vulnerable to XML External Entity Injection (XXE)

Share this post:

An XML External Entity Injection (XXE) vulnerability in InfoSphere Information Server Manager can potentially be used by an attacker to retrieve sensitive documents. Information Server Manager has a bulk import feature to help users import lists of Source Control Module (SCM) websites or user names. Use case examples for the bulk load feature are: – Multiple users want to use the SCM and there are three or more sites that need to be added. – DataStage version upgrades (i.e. version 11.3 to version 11.5) IBM Information Server Manager uses XML format for export and import of the SCM web site name and the links. Information Server Manager also allows the same information to be keyed in manually into the Add Available Software Sites dialog. There is a potential vulnerability when importing the website list using XML import.

CVE(s): CVE-2018-1727

Affected product(s) and affected version(s):

The following products, running on all supported platforms, are affected:
IBM InfoSphere Information Server: versions 9.1, 11.3, 11.5, and 11.7
IBM InfoSphere Information Server on Cloud: versions 11.5, and 11.7

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10718887
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/147630

More stories

IBM Security Bulletin: IBM Event Streams is affected by Apache ZooKeeper vulnerability CVE-2019-0201

Jul 17, 2019 9:02 am EDT | High Severity

IBM Event Streams has addressed the following vulnerability. CVE(s): CVE-2019-0201 Affected product(s) and affected version(s):IBM Event Streams 2018.3.0 IBM Event Streams 2018.3.1 IBM Event Streams 2019.1.1 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10888067X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/161303 ...read more


IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Integration Designer

Jul 17, 2019 9:02 am EDT | High Severity

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 7 and Version 8 that affect IBM Integration Designer for IBM Business Process Manager (BPM) and IBM Business Automation Workflow. Integration Designer has addressed the applicable CVEs. CVE(s): CVE-2019-2602, CVE-2019-2684 Affected product(s) and affected version(s): IBM Integration Designer V8.5.0.1, V8.5.5, V8.5.6, V8.5.7, V18.0.0.1, V18.0.0.2, ...read more


IBM Security Bulletin: IBM Event Streams is affected by kubectl vulnerabilities

Jul 17, 2019 9:02 am EDT | High Severity

IBM Event Streams has addressed the following vulnerabilities in the kubectl versions shipped. CVE(s): CVE-2019-1002101, CVE-2019-11244 Affected product(s) and affected version(s):IBM Event Streams 2018.3.0 IBM Event Streams 2018.3.1 IBM Event Streams 2019.1.1 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10888071X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/158804X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/160042 ...read more