Описание
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IBM X-Force ID: 165812.
Ссылки
- VDB EntryVendor Advisory
- PatchVendor Advisory
- VDB EntryVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ibm:security_directory_server:6.4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00339
Низкий
7.1 High
CVSS3
7.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-91
Связанные уязвимости
CVSS3: 7.1
github
больше 3 лет назад
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IBM X-Force ID: 165812.
EPSS
Процентиль: 56%
0.00339
Низкий
7.1 High
CVSS3
7.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-91