CVE-2017-1289 describes an XML External Entity (XXE) injection vulnerability in the IBM SDK, Java Technology Edition, affecting its processing of XML data. This high-severity flaw (CVSS 8.2) allows a remote, unauthenticated attacker to potentially expose sensitive information or cause denial of service by consuming memory resources. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the inherent risk of XXE vulnerabilities warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6CPE matchmatch criteria | cpe:2.3:a:ibm:sdk:*:service_refresh_16_fp41:*:*:java_technology_edition:*:*:* | ||
<= 6r1CPE matchmatch criteria | cpe:2.3:a:ibm:sdk:*:service_refresh_8_fp41:*:*:java_technology_edition:*:*:* | ||
<= 7CPE matchmatch criteria | cpe:2.3:a:ibm:sdk:*:service_refresh_10_fp1:*:*:java_technology_edition:*:*:* | ||
<= 7r1CPE matchmatch criteria | cpe:2.3:a:ibm:sdk:*:service_refresh_4_fp1:*:*:java_technology_edition:*:*:* | ||
<= 8CPE matchmatch criteria | cpe:2.3:a:ibm:sdk:*:service_refresh_4_fp2:*:*:java_technology_edition:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.