CVE-2014-4769
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity…
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- ibm/websphere commerce
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR49897
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR50553
- http://www-01.ibm.com/support/docview.wss?uid=swg21685464Vendor Advisory
- http://www.securityfocus.com/bid/70872
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94836
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR49897
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR50553
- http://www-01.ibm.com/support/docview.wss?uid=swg21685464Vendor Advisory
- http://www.securityfocus.com/bid/70872
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94836
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.