Impact
IBM i WebSphere Application Server Liberty suffers from improper processing of XML external entities, allowing a remote authenticated attacker to direct the server to resolve external entities and read sensitive files or data. The weakness, identified as CWE‑611, can result in the disclosure of confidential information accessible to a user with legitimate credentials.
Affected Systems
Affected are IBM i releases 7.3, 7.4, 7.5, and 7.6. PTFs that address the issue include SJ10874 and SJ11023 for 7.6, SJ10875 and SJ11024 for 7.5, SJ10876 and SJ11025 for 7.4, and SJ10877 and SJ11026 for 7.3. Users on other or unsupported releases are also advised to upgrade to a supported, fixed version.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting low to moderate exploitation probability. The attack requires valid authentication to the WebSphere Application Server; once authenticated, the attacker can craft XML to leverage the vulnerability and access sensitive information.
OpenCVE Enrichment