Lucene search

K
ibmIBM0D8D8D10AB97924990275171245762F7FDA8AFCE41358626998DFA506467B3B3
HistoryJan 28, 2021 - 6:05 p.m.

Security Bulletin: ViewONE is vulnerable to XXE attack when opening PDF documents

2021-01-2818:05:24
www.ibm.com
10
viewone
xxe attack
pdf documents
vulnerability
xml injection
ibm daeja virtual

EPSS

0.001

Percentile

41.2%

Summary

ViewONE is vulnerable to XXE attack when opening PDF documents.

Vulnerability Details

CVEID: CVE-2018-1835 DESCRIPTION: IBM Daeja Virtual is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CVSS Base Score: 7.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/150514&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L)

Affected Products and Versions

Daeja ViewONE 5.0

Remediation/Fixes

Updgrade to the version 5.0.4 iFix 6 or later.

EPSS

0.001

Percentile

41.2%

Related for 0D8D8D10AB97924990275171245762F7FDA8AFCE41358626998DFA506467B3B3