First published: Tue Mar 20 2018(Updated: )
XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory consumption) via crafted XML data. IBM X-Force ID: 108357.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections | <=3.0.1.1 | |
IBM Connections | =4.0.0.0 | |
IBM Connections | =4.5.0.0 | |
IBM Connections | =5.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7461 is an XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4.
CVE-2015-7461 allows remote authenticated users to cause a denial of service (memory consumption) through crafted XML data.
CVE-2015-7461 has a severity rating of 6.5 (medium).
IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 are affected by CVE-2015-7461.
To fix CVE-2015-7461, apply the necessary patches or updates provided by IBM.