First published: Thu Dec 18 2014(Updated: )
The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-6166 is classified as high due to the potential for remote file access by attackers.
To fix CVE-2014-6166, you should update to IBM WebSphere Application Server version 8.0.0.10 or later, or 8.5.5.4 or later.
The affected versions for CVE-2014-6166 include IBM WebSphere Application Server 8.0.x prior to 8.0.0.10 and 8.5.x prior to 8.5.5.4.
CVE-2014-6166 allows attackers to read arbitrary files on the server, potentially exposing sensitive information.
Mitigation options for CVE-2014-6166 include disabling XML external entity processing if possible, but updating is the recommended approach.