Thursday, April 5, 2018

IBM Security Bulletin: XML External Entity Injection (XXE) Vulnerability Impacts IBM Campaign (CVE-2015-0254)

Share this post:

Apache Standard Taglibs could allow a remote attacker to execute arbitrary code on the system, caused by an XML External Entity Injection (XXE) error when processing XML data. By sending specially crafted XML data, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE(s): CVE-2015-0254

Affected product(s) and affected version(s):

IBM Campaign 9.1, 10.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg22015263
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/101550



from IBM Product Security Incident Response Team https://ift.tt/2GXxWux

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.