First published: Fri Nov 25 2016(Updated: )
The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Reporting Service | =6.0 | |
IBM Jazz Reporting Service | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0319 has a medium severity rating as it allows remote authenticated administrators to read arbitrary files or potentially cause a denial of service.
To resolve CVE-2016-0319, you should apply the latest iFix for IBM Jazz Reporting Service 6.0.1, specifically iFix006 or later.
IBM Jazz Reporting Service versions 6.0 and 6.0.1 prior to iFix006 are affected by CVE-2016-0319.
CVE-2016-0319 facilitates attacks that can lead to unauthorized file access or denial of service through malicious XML documents.
Yes, exploitation of CVE-2016-0319 requires remote authenticated access to the IBM Jazz Reporting Service.