CVE Published: 25/04/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: ibm |
Vendor: IBM |
Product: UrbanCode Deploy Status : PUBLISHED
CVE-2017-1149 Description
IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 122202.