Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56970
HistoryAug 04, 2022 - 12:00 a.m.

IBM DataPower Gateway XML External Entity Injection Vulnerability (CNVD-2022-56970)

2022-08-0400:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
ibm datapower gateway
xml
external entity injection
vulnerability
network system
remote attacker
specially crafted xml file
file reading

EPSS

0.002

Percentile

52.0%

IBM DataPower Gateway is a set of security and integration platforms from IBM USA designed specifically for mobile, cloud, application programming interface (API), web, service-oriented architecture (SOA), B2B, and cloud workloads. The platform protects, integrates, and optimizes access across channels using a dedicated gateway platform.IBM DataPower Gateway suffers from an XML external entity injection vulnerability that stems from a network system or product that does not set the correct filtering to allow references to external entities, which can be exploited by a remote attacker to read a file by sending a specially crafted XML file.

EPSS

0.002

Percentile

52.0%

Related for CNVD-2022-56970