CVE-2017-1289
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 3.6%
exploitation probability
3.6%top 12% of all CVEs
observed exploitation
nono source reports it
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.
Affected products
IBM Corporation · Runtimes for Java Technology