CVE-2016-0288
Summary
| CVE | CVE-2016-0288 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-06-01 15:59:00 UTC |
| Updated | 2016-11-30 03:02:00 UTC |
| Description | IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Security Appscan | 8.7.0.0 | All | All | All |
| Application | Ibm | Security Appscan | 8.7.0.1 | All | All | All |
| Application | Ibm | Security Appscan | 8.8.0.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.0.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.0.1 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.1.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.1.1 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.2.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.2.1 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.3.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.3.1 | All | All | All |
| Application | Ibm | Security Appscan | 8.7.0.0 | All | All | All |
| Application | Ibm | Security Appscan | 8.7.0.1 | All | All | All |
| Application | Ibm | Security Appscan | 8.8.0.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.0.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.0.1 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.1.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.1.1 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.2.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.2.1 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.3.0 | All | All | All |
| Application | Ibm | Security Appscan | 9.0.3.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM notice: The page you requested cannot be displayed | CONFIRM | www-01.ibm.com | Vendor Advisory |
| IBM Security AppScan XML External Entity Processing Flaw Lets Remote Users Obtain Potentially Sensitive Information - SecurityTracker | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.