Medium Severity

Security Bulletin: Apache Wink as used by IBM Disconnected Log Collector is vulnerable to an XML External Entity Error (XXE) (CVE-2010-2245)

Share this post:

Apache Wink as used by IBM Disconnected Log Collector is vulnerable to an XML External Entity Error (XXE)

CVE(s): CVE-2010-2245

Affected product(s) and affected version(s):

IBM Disconnected Log Collector v1.0 – v1.6

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6494733
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/134129

More stories

Security Bulletin: Vulnerabilities in Apache Log4j affect IBM App Connect Enterprise V11, V12 and IBM Integration Bus V10 (CVE-2021-44832)

Jan 28, 2022 7:05 pm EST | Medium Severity

Vulnerabilities in Apache Log4j affect the logging infrastructure in the Kafka Nodes in IBM App Connect Enterprise v11, v12 and IBM Integration Bus v10 and the logging infrastructure in the TADataCollector command line tool in IBM App Connect Enterprise v11, v12. IBM App Connect Enterprise V11, V12 and IBM Integration Bus v10 have addressed the applicable CVE. Given current information and analysis, IBM Integration Bus V9 is not affected ...read more


Security Bulletin: A vulnerability in Apache Log4j affects some features of IBM® Db2® (CVE-2021-44832)

Jan 28, 2022 7:04 pm EST | Medium Severity

The Apache Log4j open source library used by IBM® Db2® is affected by a vulnerability that could allow a remote attacker to execute arbitrary code on the system. This library is used by the Db2 Federation feature. The fix for the vulnerability is to update the log4j library to version 2.17.1. ...read more


Security Bulletin: Vulnerability inApache Log4j – CVE-2021-44832 may affect IBM Watson Assistant for IBM Cloud Pak for Data

Jan 27, 2022 7:01 pm EST | Medium Severity

A potential vulnerability inApache Log4j - CVE-2021-44832 has been identified that may affect IBM Watson Assistant for IBM Cloud Pak for Data.  Several components of IBM Watson Assistant for IBM Cloud Pak for Data use Log4j to log diagnostic data unrelated to customer input. Refer to details for additional information. ...read more