CVE-2024-47113

EUVD-2024-42873
IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted XML statements, which would allow them to attacker to view or modify information in the XML document.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
ibmCNA
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
ibmvoice_gateway
1.0.2
ibmvoice_gateway
1.0.2.4
ibmvoice_gateway
1.0.3
ibmvoice_gateway
1.0.4
ibmvoice_gateway
1.0.5
ibmvoice_gateway
1.0.6
ibmvoice_gateway
1.0.7
ibmvoice_gateway
1.0.7.1
ibmvoice_gateway
1.0.8
𝑥
= Vulnerable software versions