CVE-2016-9698: XEE
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999960.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9698?
CVE-2016-9698 has a Medium severity rating due to its potential for denial of service.
How do I fix CVE-2016-9698?
To fix CVE-2016-9698, upgrade to a patched version of IBM Rhapsody Design Manager as specified by IBM.
What attack vector is associated with CVE-2016-9698?
CVE-2016-9698 can be exploited through XML External Entity Injection (XXE) when processing XML data.
What versions of IBM Rhapsody Design Manager are affected by CVE-2016-9698?
CVE-2016-9698 affects IBM Rhapsody Design Manager versions 4.0, 5.0, and 6.0.
What are the potential impacts of exploiting CVE-2016-9698?
Exploitation of CVE-2016-9698 can lead to denial of service and exposure of sensitive information.