First published: Mon Jun 28 2021(Updated: )
Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Infoblox NIOS | >=8.4.0<=8.4.8 | |
Infoblox NIOS | =8.5.0 | |
Infoblox NIOS | =8.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15303 is classified as a medium-severity vulnerability.
To mitigate CVE-2020-15303, upgrade Infoblox NIOS to version 8.5.2 or later.
CVE-2020-15303 allows for entity expansion attacks during XML upload operations, potentially leading to denial of service.
CVE-2020-15303 affects Infoblox NIOS versions 8.4.0 to 8.5.1 inclusive.
CVE-2020-15303 can be exploited remotely during an XML upload operation.