First published: Sun Jul 17 2016(Updated: )
IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Notes Traveler | =8.5.3 | |
IBM Notes Traveler | =9.0 | |
IBM Notes Traveler | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3039 is considered a high severity vulnerability due to its potential to allow unauthorized file access and denial of service.
To fix CVE-2016-3039, upgrade IBM Traveler to version 9.0.1.12 or later.
CVE-2016-3039 can be exploited through XXE injection attacks, leading to file reading and denial of service.
CVE-2016-3039 affects users of IBM Traveler versions 8.x and 9.x prior to version 9.0.1.12.
CVE-2016-3039 specifically affects IBM Notes Traveler versions 8.5.3 and 9.0 up to 9.0.1.