First published: Fri Mar 13 2015(Updated: )
IBM WebSphere Commerce 7.0 Feature Pack 4 through 8 allows remote attackers to read arbitrary files and possibly obtain administrative privileges via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0133 is considered to have a high severity due to the potential for remote attackers to read arbitrary files.
To fix CVE-2015-0133, ensure that XML external entity processing is disabled in IBM WebSphere Commerce configurations.
CVE-2015-0133 is related to XML External Entity (XXE) attacks which can lead to sensitive data exposure.
CVE-2015-0133 affects IBM WebSphere Commerce versions 7.0 Feature Pack 4 through 8.
Yes, CVE-2015-0133 potentially allows attackers to obtain administrative privileges through file reading exploits.