IBM.Operational.Decision.Manager.XXE

description-logoDescription

This indicates an attack attempt against a XML external entity (XXE) vulnerability in IBM Operational Decision Management.
The vulnerabilities is due to an error in the application when handling a crafted XML file. A remote attacker can exploit this to gain unauthorized access to sensitive information, or to execute arbitrary code as the target software, via a crafted XML file.

affected-products-logoAffected Products

IBM Operational Decision Management version 8.6.0.0 to version 8.6.0.2
IBM Operational Decision Management version 8.7.0.0 to version 8.7.1.2
IBM Operational Decision Management version 8.8.0.0 to version 8.8.1.2
IBM Operational Decision Management version 8.9.0.0 to version 8.9.2.0

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://exchange.xforce.ibmcloud.com/vulnerabilities/150170

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-11-13 14.723 Default_action:pass:drop
2019-10-30 14.714

References

46017