CVE-2019-4456: IBM Daeja Viewone
High severity, CVSS 7.1. EPSS: 1.9% chance of exploitation in the next 30 days.
IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 163620.
Affected products
- IBM Daeja Viewone: from 5.0, up to and including 5.0.6
Published 2019-07-30. Last modified 2026-06-17.