Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hpm7-9wr3-ccfg

Опубликовано: 18 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15

is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15

is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.

EPSS

Процентиль: 23%
0.00078
Низкий

8.8 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.8
nvd
8 месяцев назад

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.

EPSS

Процентиль: 23%
0.00078
Низкий

8.8 High

CVSS3

Дефекты

CWE-611