Lucene search

K
cveIbmCVE-2023-50304
HistoryJul 18, 2024 - 4:15 p.m.

CVE-2023-50304

2024-07-1816:15:06
CWE-611
ibm
web.nvd.nist.gov
10
ibm
requirements management
xml external entity injection

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.3%

IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 273335.

Affected configurations

Vulners
Node
ibmengineering_requirements_management_doorsMatch9.7.2.8
VendorProductVersionCPE
ibmengineering_requirements_management_doors9.7.2.8cpe:2.3:a:ibm:engineering_requirements_management_doors:9.7.2.8:*:*:*:*:*:*:*

CNA Affected

[
  {
    "cpes": [
      "cpe:2.3:a:ibm:engineering_requirements_management_doors:9.7.2.7:*:*:*:*:*:*:*"
    ],
    "defaultStatus": "unaffected",
    "product": "Engineering Requirements Management DOORS",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "9.7.2.8"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.3%

Related for CVE-2023-50304