Vulnerability Name: | CVE-2016-0288 (CCN-111297) | ||||||||||||
Assigned: | 2015-12-08 | ||||||||||||
Published: | 2016-06-01 | ||||||||||||
Updated: | 2016-11-30 | ||||||||||||
Summary: | IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. CWE-611: Improper Restriction of XML External Entity Reference ('XXE') | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-0288 Source: CCN Type: IBM Security Bulletin XML External Entity Injection affect AppScan Standard (CVE-2016-0288) Source: CCN Type: IBM Security Bulletin 1987707 (Security AppScan Enterprise) Multiple Vulnerabilities in AppScan Enterprise (CVE-2016-2107, CVE-2016-2105, CVE-2016-0288) Source: CCN Type: BID-90735 IBM Security AppScan CVE-2016-0288 XML External Entity Information Disclosure Vulnerability Source: XF Type: UNKNOWN ibm-appscan-cve20160228-info-disc(111297) | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |