CVE-2017-1289
Publication date 22 May 2017
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ibm-java80 | 18.04 LTS bionic |
Fixed 8.0.5.16-0ubuntu1
|
| 16.04 LTS xenial |
Fixed 8.0.5.16-0ubuntu1
|
|
| 14.04 LTS trusty | Not in release |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
8.2 · High
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L