Lucene search

K
ibmIBM1F7D5834B6F260C5AD82579049182022D4DE2599980D4A91ECE0C0BED4C84B50
HistoryApr 13, 2023 - 7:24 p.m.

Security Bulletin:IBM TRIRIGA Application Platform discloses XML external entities injection (CVE-2023-27876)

2023-04-1319:24:43
www.ibm.com
14
ibm tririga
xml external entities
injection
vulnerability
cvss
fix
download

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

0.001 Low

EPSS

Percentile

38.5%

Summary

IBM TRIRIGA Application Platform discloses XML external entities injection

Vulnerability Details

CVEID:CVE-2023-27876
**DESCRIPTION:**IBM Tririga is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CVSS Base score: 7.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/249975 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM TRIRIGA Application Platform 4.0

Remediation/Fixes

Product|VRMF|

Remediation/First Fix

—|—|—
IBM TRIRIGA Application Platform| 4.0| The fix is available for download on FixCentral.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtririga_application_platformMatch4.0
CPENameOperatorVersion
ibm tririga application platformeq4.0

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

0.001 Low

EPSS

Percentile

38.5%

Related for 1F7D5834B6F260C5AD82579049182022D4DE2599980D4A91ECE0C0BED4C84B50