Description
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
Affected products
- IBM Corporation / InfoSphere Information Server8.1 – 8.1
- IBM Corporation / InfoSphere Information Server8.5 – 8.5
- IBM Corporation / InfoSphere Information Server8.0 – 8.0
- IBM Corporation / InfoSphere Information Server8.5.0.1 – 8.5.0.1
- IBM Corporation / InfoSphere Information Server8.7 – 8.7
- IBM Corporation / InfoSphere Information Server9.1 – 9.1
- IBM Corporation / InfoSphere Information Server8.0.1 – 8.0.1
- IBM Corporation / InfoSphere Information Server10.0 – 10.0
- IBM Corporation / InfoSphere Information Server11.3 – 11.3
- IBM Corporation / InfoSphere Information Server10 – 10
- IBM Corporation / InfoSphere Information Server11.3.0.0 – 11.3.0.0
- IBM Corporation / InfoSphere Information Server11.3.1.0 – 11.3.1.0
- IBM Corporation / InfoSphere Information Server11.5 – 11.5