XML External Entity Vulnerability in IBM Rational Products
CVE-2016-0284
5.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 24 November 2016
What is CVE-2016-0284?
An XML External Entity vulnerability exists in several IBM Rational products due to an insecure XML parser configuration. This flaw can potentially allow remote authenticated users to exploit XML documents containing external entity declarations, enabling them to read arbitrary files on the server or trigger a denial-of-service condition. Organizations utilizing affected versions should promptly apply security fixes to safeguard their environments against these risks.