CVE-2024-54171

high

Description

IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

References

https://www.ibm.com/support/pages/node/7182693

Details

Source: Mitre, NVD

Published: 2025-02-06

Updated: 2025-07-07

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:P

Severity: High

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Severity: High

EPSS

EPSS: 0.00065