CVE-2016-9706: XEE
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997918.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9706?
CVE-2016-9706 has a medium severity rating due to its potential to cause a denial of service.
How do I fix CVE-2016-9706?
To mitigate CVE-2016-9706, it is recommended to apply the patches provided by IBM for affected software versions.
Which software versions are affected by CVE-2016-9706?
CVE-2016-9706 affects IBM Integration Bus versions 9.0 and 10.0, as well as IBM WebSphere Message Broker version 8.0.
What type of vulnerability is CVE-2016-9706?
CVE-2016-9706 is classified as an XML External Entity Injection (XXE) vulnerability.
Can CVE-2016-9706 lead to data exposure?
Yes, CVE-2016-9706 can potentially allow remote attackers to expose highly sensitive information.