First published: Wed Feb 21 2018(Updated: )
XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 112088.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Forms Experience Builder | =8.5 | |
IBM Forms Experience Builder | =8.5.1 | |
IBM Forms Experience Builder | =8.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0369 has been classified with a moderate severity level due to its potential for sensitive information disclosure.
To fix CVE-2016-0369, update your IBM Forms Experience Builder to the latest available version that addresses this vulnerability.
CVE-2016-0369 allows remote authenticated users to access sensitive information from the server by exploiting XML external entity injections.
Users of IBM Forms Experience Builder versions 8.5, 8.5.1, and 8.6 are affected by CVE-2016-0369.
CVE-2016-0369 is not classified as critical, but it poses a significant risk if exploited in environments handling sensitive data.