CVE Vulnerabilities

CVE-2016-0245

Published: Feb 29, 2016 | Modified: Feb 19, 2017
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticated users to read arbitrary files or cause a denial of service via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected Software

Name Vendor Start Version End Version
Websphere_portal Ibm 8.5.0.0 8.5.0.0
Websphere_portal Ibm 8.0.0.1 8.0.0.1
Websphere_portal Ibm 8.0.0.0 8.0.0.0

References