IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CVE ID: CVE-2024-54171
CVSS Base Severity: HIGH
CVSS Base Score: 7.1
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Vendor: IBM
Product: EntireX
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 21.09% (scored less or equal to compared to others)
EPSS Date: 2025-03-07 (when was this score calculated)