First published: Thu Dec 01 2016(Updated: )
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL AppScan Source | =8.7 | |
HCL AppScan Source | =8.7.0.1 | |
HCL AppScan Source | =8.8 | |
HCL AppScan Source | =9.0 | |
HCL AppScan Source | =9.0.0.1 | |
HCL AppScan Source | =9.0.1 | |
HCL AppScan Source | =9.0.2 | |
HCL AppScan Source | =9.0.3 | |
HCL AppScan Source | =9.0.3.1 | |
HCL AppScan Source | =9.0.3.2 | |
HCL AppScan Source | =9.0.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3033 has a medium severity rating, primarily due to the risk of data exposure and potential denial of service.
To fix CVE-2016-3033, upgrade to a patched version of IBM AppScan Source beyond 9.0.3.3.
CVE-2016-3033 can facilitate XML External Entity (XXE) attacks, allowing unauthorized file reading or memory consumption.
CVE-2016-3033 affects IBM AppScan Source versions 8.7 through 9.0.3.3.
Remote authenticated users of vulnerable IBM AppScan Source versions are at risk due to CVE-2016-3033.