Vulnerability CVE-2016-0219


Published: 2018-01-16

Description:
XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data. IBM X-Force ID: 109693.

Type:

CWE-611

(Information Exposure Through XML External Entity Reference)

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
IBM -> Rational collaborative lifecycle management 
IBM -> Rational doors next generation 
IBM -> Rational engineering lifecycle manager 
IBM -> Rational quality manager 
IBM -> Rational requirements composer 
IBM -> Rational rhapsody design manager 
IBM -> Rational software architect design manager 
IBM -> Rational team concert 

 References:
http://www-01.ibm.com/support/docview.wss?uid=swg21983720
https://exchange.xforce.ibmcloud.com/vulnerabilities/109693

Copyright 2024, cxsecurity.com

 

Back to Top