Sceawere

Vulnerability Detail

CVE-2026-18715UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i XML External Entity Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-611 Improper Restriction of XML External Entity Reference
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-13T21:17:45.537Z",
  "pubdate": "2026-08-13T21:17:45.537Z",
  "executiveSummary": "An information disclosure vulnerability exists in IBM i versions 7.6, 7.5, 7.4, and 7.3 that arises from the improper processing of XML external entities (XXE). This security flaw allows a remote authenticated attacker to interact with the underlying system or connected networks by supplying specially crafted XML input containing external entity references.\nThe primary impact of successful exploitation is the unauthorized retrieval of sensitive information accessible to the application parsing the XML data. This may include internal configuration data, sensitive file contents, or internal network service responses that are otherwise restricted.\nThe affected products are IBM i 7.6, 7.5, 7.4, and 7.3. The risk implications involve potential confidentiality breaches depending on what internal resources the parser can access. Exploitation requires remote authentication against the target system, meaning the attacker must possess valid credentials to interact with the vulnerable XML processing component.",
  "technicalDetails": "The root cause of the vulnerability resides in the insecure configuration or improper implementation of the XML parsing engine within the affected IBM i components. Specifically, the XML parser fails to adequately disable the resolution and processing of external entity references defined within the Document Type Definition (DTD) of submitted XML documents.\nThe affected components are the XML parsing engines utilized across IBM i 7.6, 7.5, 7.4, and 7.3. Network exposure depends on the specific service or application interface accepting XML input, which is typically accessible over standard network protocols utilized by the operating system or its integrated subsystems. Authentication requirements dictate that the attacker must be a remote authenticated user to submit the payload to the vulnerable endpoint.\nThe exploitation method relies on supplying a malicious XML payload containing a custom DTD declaration that defines an external entity pointing to a local file path or a remote URI. When the vulnerable parser processes the incoming XML document, it evaluates the external entity by attempting to read the referenced resource.\nThe step-by-step attack flow proceeds as follows: First, the remote authenticated attacker crafts an XML payload embedding an external entity reference, such as file:///etc/passwd or a targeted internal resource. Second, the attacker transmits this payload to the vulnerable XML-processing interface on the IBM i system. Third, the XML parser on the target system parses the document and resolves the external entity by fetching the requested resource. Finally, the parser incorporates the content of the retrieved resource into the application response or handles it in a way that allows the attacker to view or infer the sensitive data, leading to information disclosure."
}
CVE-2026-18715: IBM i XML External Entity Information Disclosure (MEDIUM Severity, CVSS: 6.5) - Sceawere