First published: Wed Jun 01 2016(Updated: )
IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security AppScan | =8.7.0.0 | |
IBM Security AppScan | =8.7.0.1 | |
IBM Security AppScan | =8.8.0.0 | |
IBM Security AppScan | =9.0.0.0 | |
IBM Security AppScan | =9.0.0.1 | |
IBM Security AppScan | =9.0.1.0 | |
IBM Security AppScan | =9.0.1.1 | |
IBM Security AppScan | =9.0.2.0 | |
IBM Security AppScan | =9.0.2.1 | |
IBM Security AppScan | =9.0.3.0 | |
IBM Security AppScan | =9.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0288 is classified as a high severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2016-0288, upgrade IBM Security AppScan to version 9.0.3.2 or later to mitigate the vulnerability.
CVE-2016-0288 affects IBM Security AppScan Standard versions 8.7.x, 8.8.x, and 9.x prior to 9.0.3.2.
Yes, CVE-2016-0288 can be exploited by remote authenticated users to read arbitrary files on the server.
CVE-2016-0288 is associated with XML External Entity (XXE) attacks, which leverage external entity declarations in XML.