CVE-2019-4062
Description
IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 157007.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM i2 Intelligent Analysis Platform 9.0.0-9.1.1 vulnerable to XXE, allowing remote attackers to access sensitive information or exhaust memory.
Vulnerability
IBM i2 Intelligent Analysis Platform versions 9.0.0 through 9.1.1, including IBM i2 Analyst's Notebook and Analyst's Notebook Premium, are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. The vulnerability is present in the XML parser's handling of external entities, requiring no special configuration beyond default settings [1].
Exploitation
A remote attacker with low privileges (network access and valid credentials) can craft a malicious XML payload containing an external entity reference. Upon processing by the vulnerable component, the XML parser resolves the external entity, leading to information disclosure or resource consumption. No user interaction is required beyond the system processing the attacker-supplied XML [1].
Impact
Successful exploitation allows the attacker to expose sensitive information (confidentiality impact: high) or cause denial of service via memory consumption (availability impact: low). The attacker does not gain direct code execution but can read arbitrary files or perform server-side request forgery (SSRF) to internal resources [1].
Mitigation
IBM has released fixes for the affected versions. Administrators should apply the appropriate patch or upgrade as specified in the security bulletin (ibm10881746). As of the publication date (2019-07-30), no workarounds are documented, and the vendor strongly recommends updating to a fixed release [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: >=9.0.0, <=9.1.1
- IBM/i2 Analyst's Notebookv5Range: 9.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.ibm.com/support/docview.wssmitrex_refsource_CONFIRM
- exchange.xforce.ibmcloud.com/vulnerabilities/157007mitrevdb-entryx_refsource_XF
News mentions
0No linked articles in our index yet.