XML External Entity (XXE) Vulnerability in IBM WebSphere Portal

XML External Entity (XXE) Vulnerability in IBM WebSphere Portal

CVE-2016-0245 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:N/A:P

The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticated users to read arbitrary files or cause a denial of service via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Learn more about our Cis Benchmark Audit For Ibm I.