CVE-2024-45072: IBM WebSphere Application Server XML external entity injection
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM WebSphere Application Server is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45072?
CVE-2024-45072 is classified as a moderate severity vulnerability due to its potential for information disclosure and resource consumption.
How do I fix CVE-2024-45072?
To fix CVE-2024-45072, update your IBM WebSphere Application Server to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-45072?
CVE-2024-45072 affects users of IBM WebSphere Application Server versions 8.5 and 9.0, up to specific patch levels.
What is an XML External Entity Injection (XXE) in relation to CVE-2024-45072?
XML External Entity Injection (XXE) in CVE-2024-45072 allows attackers to manipulate XML data processing, potentially leading to unauthorized data access.
What type of data can be exposed due to CVE-2024-45072?
Due to CVE-2024-45072, sensitive information such as configuration files and internal documents may be exposed if the vulnerability is exploited.