CVE-2023-50304: IBM Engineering Requirements Management DOORS XML external entity injection
IBM DOORS Web Access is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 273335.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50304?
CVE-2023-50304 is considered a high severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2023-50304?
To fix CVE-2023-50304, update IBM Engineering Requirements Management DOORS and IBM DOORS Web Access to version 9.7.2.8 or later.
What types of attacks are possible with CVE-2023-50304?
CVE-2023-50304 allows attackers to perform XML External Entity Injection, potentially leading to information disclosure and resource consumption.
What software versions are affected by CVE-2023-50304?
CVE-2023-50304 affects IBM Engineering Requirements Management DOORS and DOORS Web Access versions up to 9.7.2.8, as well as IBM® Rational DOORS/DOORS Web Access versions up to 9.6.1.x.
Is CVE-2023-50304 exploit practical?
Yes, CVE-2023-50304 is practical for attackers as it can be exploited remotely with the right conditions.