CVE-2016-3027: XEE
IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3027?
CVE-2016-3027 has a medium severity rating due to its potential for denial of service and exposure of sensitive information.
How do I fix CVE-2016-3027?
To fix CVE-2016-3027, apply the latest security patches from IBM for the affected versions of IBM Security Access Manager.
What systems are affected by CVE-2016-3027?
CVE-2016-3027 affects IBM Security Access Manager for Web versions 8.0.0 to 8.0.1.4 and IBM Security Access Manager for Mobile versions 8.0.0.1 to 8.0.1.4.
Can CVE-2016-3027 lead to data loss?
Yes, CVE-2016-3027 could potentially lead to data loss if exploited to exhaust memory resources.
Is CVE-2016-3027 being actively exploited?
As of the last updates, there were no public reports confirming active exploitation of CVE-2016-3027.