XML External Entity Vulnerability in IBM SPSS Collaboration and Deployment Services
CVE-2013-4069
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 21 December 2013
What is CVE-2013-4069?
The Portal application in IBM SPSS Collaboration and Deployment Services versions prior to 4.2.1.3 IF3 and 5.0 before FP3 is prone to XML External Entity (XXE) vulnerabilities, which allow remote attackers to read arbitrary files on the server. This security flaw results from improper handling of XML input, leading to a scenario where an external XML entity can be declared and referenced. Exploitation of this vulnerability could lead to exposure of sensitive information and pose a significant security risk to affected systems.