CVE-2016-0268: XEE
XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 110915.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2016-0268.
What is the severity of CVE-2016-0268?
The severity of CVE-2016-0268 is medium.
Which software is affected by CVE-2016-0268?
IBM Financial Transaction Manager (FTM) for ACH Services, Financial Transaction Manager (FTM) for Check Services, and Financial Transaction Manager (FTM) for CPS Services are affected by CVE-2016-0268.
What is the version range of the affected software?
The affected versions of the software range from 2.1.1.2 to 3.0.0.12.
How can I fix CVE-2016-0268?
Apply fp0013 for Multi-Platform 2.1.1.2 and 3.0.0.x versions of IBM Financial Transaction Manager (FTM) for ACH Services, Financial Transaction Manager (FTM) for Check Services, and Financial Transaction Manager (FTM) for CPS Services.