VulnerabilityModified
CVE-2016-0250
XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data.
MEDIUM 5.4EPSS 1.48%
Does this matter?
Lower severity and a low EPSS score (1.48%). Track it; it rarely justifies an emergency change on its own.
Description
XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data. IBM X-Force ID: 110510.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
- EPSS
- 1.48% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- ibm/infosphere information server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21977152Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/110510VDB Entry, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21977152Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/110510VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.