First published: Fri Sep 04 2015(Updated: )
The XML parser in EMC Atmos before 2.2.3.426 and 2.3.x before 2.3.1.0 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Atmos | =2.2.3 | |
EMC Atmos | =2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4538 has been classified as a medium-severity vulnerability due to its potential for denial of service and unauthorized file access.
To mitigate CVE-2015-4538, upgrade EMC Atmos to version 2.2.3.426 or 2.3.1.0 or later.
CVE-2015-4538 affects EMC Atmos versions prior to 2.2.3.426 and 2.3.x prior to 2.3.1.0.
CVE-2015-4538 can enable unauthorized file access and denial of service through XML External Entity (XXE) attacks.
There are no official workarounds for CVE-2015-4538, so upgrading the software is the recommended solution.