CVE-2018-1607

Description

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 143797.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
EPSS Score
Exploitation Probability
0.359

Associated Vulnerability

VulnerabilityOS Platform
Google Chrome (69.0.3497.81)Windows
Google Chrome (x64) (69.0.3497.81)Windows
Google Chrome (69.0.3497.92)Windows
Google Chrome (x64) (69.0.3497.92)Windows
Google Chrome (69.0.3497.100)Windows
Google Chrome (x64) (69.0.3497.100)Windows
Google Chrome (70.0.3538.77)Windows
Google Chrome (x64) (70.0.3538.77)Windows
Upgrade Foxit Reader Enterprise 9.3.0.10826 to latest versionWindows
Upgrade foxit_reader 9.3.0.10826 to latest versionWindows
Google Chrome (69.0.3497.81) (For Debian)Linux
Google Chrome (69.0.3497.92) (For Debian)Linux
Google Chrome (69.0.3497.100) (For Debian)Linux
Google Chrome (70.0.3538.77) (For Debian)Linux
Google Chrome (69.0.3497.81) (For Centos)Linux
Google Chrome (69.0.3497.92) (For Centos)Linux
Google Chrome (69.0.3497.100) (For Centos)Linux
Google Chrome (70.0.3538.77) (For Centos)Linux
Google Chrome (69.0.3497.81) (For RedHat)Linux
Google Chrome (69.0.3497.92) (For RedHat)Linux
Google Chrome (69.0.3497.100) (For RedHat)Linux
Google Chrome (70.0.3538.77) (For RedHat)Linux
Google Chrome (69.0.3497.81) (For Suse)Linux
Google Chrome (69.0.3497.92) (For Suse)Linux
Google Chrome (69.0.3497.100) (For Suse)Linux
Google Chrome (70.0.3538.77) (For Suse)Linux
Google Chrome (69.0.3497.81) (For Ubuntu)Linux
Google Chrome (69.0.3497.92) (For Ubuntu)Linux
Google Chrome (69.0.3497.100) (For Ubuntu)Linux
Google Chrome (70.0.3538.77) (For Ubuntu)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-308005Google Chrome (69.0.3497.81)
PATCH-308006Google Chrome (x64) (69.0.3497.81)
PATCH-308056Google Chrome (69.0.3497.92)
PATCH-308057Google Chrome (x64) (69.0.3497.92)
PATCH-308082Google Chrome (69.0.3497.100)
PATCH-308083Google Chrome (x64) (69.0.3497.100)
PATCH-308296Google Chrome (70.0.3538.77)
PATCH-308299Google Chrome (x64) (70.0.3538.77)
PATCH-341798Foxit PDF Reader (MSI) (2024.3.0.26795) (Formerly Foxit Reader Enterprise)
PATCH-341796Foxit Reader (2024.3.0.26795)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234