CVE-2016-0219
XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via…
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data. IBM X-Force ID: 109693.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- ibm/rational quality manager · ibm/rational requirements composer · ibm/rational doors next generation · ibm/rational team concert · ibm/rational collaborative lifecycle management · ibm/rational engineering lifecycle manager · ibm/rational rhapsody design manager · ibm/rational software architect design manager
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21983720Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/109693VDB Entry, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21983720Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/109693VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.