CVE-2016-6805: XEE
Published Apr 7, 2017
·Updated
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
Affected Software
1 affected component
Apache Ignite<=1.8
Event History
Apr 7, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6805?
CVE-2016-6805 is classified as a medium severity vulnerability due to its potential for exploit by man-in-the-middle attackers.
2
How do I fix CVE-2016-6805?
To fix CVE-2016-6805, upgrade Apache Ignite to version 1.9 or later where the vulnerability has been addressed.
3
What type of attacks does CVE-2016-6805 allow?
CVE-2016-6805 allows man-in-the-middle attackers to perform unauthorized file reads through XML External Entity (XXE) processing.
4
Which versions of Apache Ignite are affected by CVE-2016-6805?
Apache Ignite versions prior to 1.9, specifically up to 1.8, are affected by CVE-2016-6805.
5
What is the cause of CVE-2016-6805 vulnerability?
CVE-2016-6805 is caused by improper handling of XML External Entities (XXE) in modified update-notifier documents.