Vulnerability Name: | CVE-2017-16931 (CCN-135488) | ||||||||||||||||||||
Assigned: | 2017-11-23 | ||||||||||||||||||||
Published: | 2017-11-23 | ||||||||||||||||||||
Updated: | 2021-07-20 | ||||||||||||||||||||
Summary: | parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name. | ||||||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-16931 Source: CCN Type: IBM Security Bulletin 2007952 (Cognos Business Intelligence) IBM Cognos Business Intelligence Server 2017Q4 Security Updater: IBM Cognos Business Intelligence Server is affected by multiple vulnerabilities. Source: CCN Type: IBM Security Bulletin 2011764 (Cognos Business Intelligence) Multiple vulnerabilities in Libxml2 affect IBM Cognos Metrics Manager. Source: CCN Type: IBM Security Bulletin 2011831 (Connections Docs) IBM Connections Docs is affected by libxml2 vulnerabilty (CVE-2017-16932 CVE-2017-16931) Source: CCN Type: IBM Security Bulletin 2013398 (PureData System for Analytics) Multiple vulnerabilities in XMLsoft Libxml2 and OpenSSL affect IBM Netezza Analytics Source: CCN Type: IBM Security Bulletin 2013890 (Lotus Protector for Mail Security) IBM Protector is affected by Open Source XMLsoft Libxml2 Vulnerabilities Source: CCN Type: IBM Security Bulletin 2014337 (Cognos Analytics) Multiple Vulnerabilities in libxml2 affects IBM Cognos Analytics Source: CCN Type: IBM Security Bulletin 2015944 (InfoSphere Identity Insight) Multiple vulnerabilities in Libxml2 affect IBM InfoSphere Identity Insight. Source: CONFIRM Type: Release Notes, Vendor Advisory http://xmlsoft.org/news.html Source: CONFIRM Type: Permissions Required https://bugzilla.gnome.org/show_bug.cgi?id=766956 Source: XF Type: UNKNOWN libxml2-cve201716931-bo(135488) Source: CCN Type: libxml2 GIT Repository Fix handling of parameter-entity references Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/GNOME/libxml2/commit/e26630548e7d138d2c560844c43820b6767251e3 Source: MLIST Type: UNKNOWN [debian-lts-announce] 20171130 [SECURITY] [DLA 1194-1] libxml2 security update Source: CCN Type: IBM Security Bulletin 6551876 (Cloud Pak for Security) Cloud Pak for Security uses packages that are vulnerable to multiple CVEs Source: CCN Type: Oracle CPUJul2021 Oracle Critical Patch Update Advisory - July 2021 Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-16931 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |