XML External Entity Issue in IBM Security AppScan Products
CVE-2016-0288

6.5MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 June 2016

Summary

Remote authenticated users in IBM Security AppScan Standard and Enterprise versions prior to 9.0.3.2 can exploit an XML External Entity (XXE) vulnerability. This vulnerability allows attackers to read arbitrary files from the server by crafting an XML document that includes an external entity declaration and an entity reference. This may expose sensitive information and compromise the integrity of the application.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.