CVE-2024-22354: IBM WebSphere Application Server XML external entity injection
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forgery attack. IBM X-Force ID: 280401.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22354?
CVE-2024-22354 has been assigned a medium severity level due to its potential impact on sensitive information exposure.
How do I fix CVE-2024-22354?
To fix CVE-2024-22354, users should update their IBM WebSphere Application Server to the latest patched version.
What products are affected by CVE-2024-22354?
CVE-2024-22354 affects IBM WebSphere Application Server versions 8.5, 9.0, and Liberty versions 17.0.0.3 through 24.0.0.5.
Can CVE-2024-22354 be exploited remotely?
Yes, CVE-2024-22354 can be exploited by a remote attacker through XML External Entity Injection.
What type of attack is CVE-2024-22354 associated with?
CVE-2024-22354 is associated with XML External Entity Injection (XXE) attacks.