XML External Entity Issue in IBM Security AppScan Products
CVE-2016-0288
6.5MEDIUM
Summary
Remote authenticated users in IBM Security AppScan Standard and Enterprise versions prior to 9.0.3.2 can exploit an XML External Entity (XXE) vulnerability. This vulnerability allows attackers to read arbitrary files from the server by crafting an XML document that includes an external entity declaration and an entity reference. This may expose sensitive information and compromise the integrity of the application.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved