CVE-2015-4538: High severity emc atmos vulnerability
The XML parser in EMC Atmos before 2.2.3.426 and 2.3.x before 2.3.1.0 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4538?
CVE-2015-4538 has been classified as a medium-severity vulnerability due to its potential for denial of service and unauthorized file access.
How do I fix CVE-2015-4538?
To mitigate CVE-2015-4538, upgrade EMC Atmos to version 2.2.3.426 or 2.3.1.0 or later.
Who is affected by CVE-2015-4538?
CVE-2015-4538 affects EMC Atmos versions prior to 2.2.3.426 and 2.3.x prior to 2.3.1.0.
What types of attacks can CVE-2015-4538 enable?
CVE-2015-4538 can enable unauthorized file access and denial of service through XML External Entity (XXE) attacks.
Are there any workarounds for CVE-2015-4538?
There are no official workarounds for CVE-2015-4538, so upgrading the software is the recommended solution.