Denial of Service Vulnerability in IBM Mashup Center
CVE-2015-7400

7.7HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
2 January 2016

Summary

The Lotus Mashups component in IBM Mashup Center 3.0.0.1 is susceptible to an XML External Entity (XXE) issue. This vulnerability enables remote authenticated users to exploit XML external entity declarations, potentially leading to significant CPU consumption and a denial of service condition. Proper handling and validation of XML data are essential to mitigate the impact of this vulnerability. Organizations using affected versions should prioritize updates and follow best practices for XML parsing.

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.