CVE-2014-6166: Medium severity ibm websphere application server feature pack for web services vulnerability
The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6166?
The severity of CVE-2014-6166 is classified as high due to the potential for remote file access by attackers.
How do I fix CVE-2014-6166?
To fix CVE-2014-6166, you should update to IBM WebSphere Application Server version 8.0.0.10 or later, or 8.5.5.4 or later.
What are the affected versions for CVE-2014-6166?
The affected versions for CVE-2014-6166 include IBM WebSphere Application Server 8.0.x prior to 8.0.0.10 and 8.5.x prior to 8.5.5.4.
What types of attacks are possible due to CVE-2014-6166?
CVE-2014-6166 allows attackers to read arbitrary files on the server, potentially exposing sensitive information.
Is there a way to mitigate CVE-2014-6166 without updating?
Mitigation options for CVE-2014-6166 include disabling XML external entity processing if possible, but updating is the recommended approach.