CVE-2017-1289

Publication date 22 May 2017

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

8.2 · High

Score breakdown

Description

IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.

Status

Package Ubuntu Release Status
ibm-java80 18.04 LTS bionic
Fixed 8.0.5.16-0ubuntu1
17.10 artful Not in release
17.04 zesty Not in release
16.10 yakkety Not in release
16.04 LTS xenial
Fixed 8.0.5.16-0ubuntu1
14.04 LTS trusty Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 8.2 · High

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L


Access our resources on patching vulnerabilities