## Summary
There is a vulnerability in Apache SOAP used by IBM Maximo Asset Management.
## Vulnerability Details
**CVEID: **[CVE-2022-40705]()
**DESCRIPTION: **Apache SOAP is vulnerable to an XML external entity injection (XXE) attack when processing XML data, caused by a weakly configured XML parser in RPCRouterServlet. By using specially-crafted XML content in the configuration file, a remote attacker could exploit this vulnerability to read arbitrary files.
CVSS Base score: 7.5
CVSS Temporal Score: See: [ https://exchange.xforce.ibmcloud.com/vulnerabilities/236814]() for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
## Affected Products and Versions
This vulnerability affects the following versions of the IBM Maximo Asset Management core product. The recommended action is to update to the latest version.
**Product versions affected:**
Affected Product(s) | Version(s)
—|—
IBM Maximo Asset Management | 7.6.1.2
IBM Maximo Asset Management | 7.6.1.3
* To determine the core product version, log in and view System Information. The core product version is the “Tivoli’s process automation engine” version. Please consult the [Platform Matrix]( “Platform Matrix” ) for a list of supported product combinations.
## Remediation/Fixes
The recommended solution is to download the appropriate Interim Fix or Fix Pack from Fix Central (What is Fix Central?) and apply for each affected product as soon as possible. Please see below for information on the fixes available for each product, version, and release. Follow the installation instructions in the âreadmeâ documentation provided with each fix pack or interim fix.
**For Maximo Asset Management 7.6:**
VRM | Fix Pack, Feature Pack, or Interim Fix | Download
—|—|—
7.6.1.2 |
Maximo Asset Management 7.6.1.2 iFix:
[7.6.1.2-TIV-MBS-IF029]( “7.6.1.2-TIV-MBS-IF029” ) or latest Interim Fix available
| [FixCentral]( “FixCentral” )
7.6.1.3 |
Maximo Asset Management 7.6.1.3 iFix:
[7.6.1.3-TIV-MBS-IF004]( “7.6.1.3-TIV-MBS-IF004” ) or latest Interim Fix available
| [FixCentral]( “FixCentral” )
## Workarounds and Mitigations
None