CVE-2016-8980: XEE
Published Feb 1, 2017
·Updated
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
Affected Software
13 affected components
IBM License Metric Tool=9.2.0
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
IBM BigFix Inventory=9.2
All of the following
IBM License Metric Tool=9.2.0
Any of the following
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8980?
CVE-2016-8980 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-8980?
To fix CVE-2016-8980, upgrade to a version of IBM BigFix Inventory that addresses the XML External Entity Injection issue.
3
What products are affected by CVE-2016-8980?
CVE-2016-8980 specifically affects IBM BigFix Inventory v9.2.0.
4
Can CVE-2016-8980 be exploited remotely?
Yes, CVE-2016-8980 can be exploited remotely by an attacker to consume memory resources or expose sensitive information.
5
What does CVE-2016-8980 exploit in IBM BigFix Inventory?
CVE-2016-8980 exploits an XML External Entity Injection vulnerability when processing XML data.