Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-1149

Опубликовано: 25 апр. 2017
Источник: nvd
CVSS3: 8.1
CVSS2: 7.5
EPSS Низкий

Описание

IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 122202.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:urbancode_deploy:6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.12:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.0.1.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.1.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.2.0.201:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:6.2.1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00359
Низкий

8.1 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 122202.

EPSS

Процентиль: 58%
0.00359
Низкий

8.1 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-611