CVE-2019-4208: IBM Tririga Application Platform

High severity, CVSS 7.1. EPSS: 1.9% chance of exploitation in the next 30 days.

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 159129.

Affected products

  • IBM Tririga Application Platform: from 3.5.3.0, before 3.5.3.6 (fixed in 3.5.3.6); from 3.6.0.0, before 3.6.0.3 (fixed in 3.6.0.3)

Published 2019-05-07. Last modified 2026-06-17.