Vulnerability information for J WBEM Server 4.x

The following is a list of the J Server vulnerability Issue that have been addressed

J WBEM Server 4.7.5



Description

There is a vulnerability in the J WBEM Server 4.x where the server is vulnerable to XML external entity injection (also known as XXE). This a vulnerability that allows an attacker to interfere with the XML parser. This attack may lead to Information Disclosure, Server Side Request Forgery, or Denial of Service.

Versions

All versions of J WBEM Server 4.x prior to version 4.7.5 are affected

CVE Information

See CVE number CVE-2023-37364 for more information

Action

Contact WS Support to get version 4.7.5 or later.

Revision History

July 27, 2023: This security information is published.