IBM Connections CVE-2015-7461 XML External Entity Denial of Service Vulnerability
BID:103486
Info
IBM Connections CVE-2015-7461 XML External Entity Denial of Service Vulnerability
| Bugtraq ID: | 103486 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-7461 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 14 2016 12:00AM |
| Updated: | Apr 14 2016 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Connections 2.0.1 0 IBM Connections 5.0 IBM Connections 4.5 IBM Connections 4.0 IBM Connections 3.0.1.1 IBM Connections 3.0.1.0 IBM Connections 2.5.0.3 IBM Connections 2.5.0.2 IBM Connections 2.5.0.1 IBM Connections 2.5.0.0 IBM Connections 2.0.1.1 IBM Connections 2.0.0.0 IBM Connections 1.0.2.0 |
| Not Vulnerable: |
IBM Connections 5.0 CR4 IBM Connections 4.5 CR5 IBM Connections 4.0 CR4 IBM Connections 3.0.1.1 CR3 |
Discussion
IBM Connections CVE-2015-7461 XML External Entity Denial of Service Vulnerability
IBM Connections is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to consume memory resources and cause a denial-of-service condition.
IBM Connections 3.0.1.1 and earlier, 4.0, 4.5 and 5.0 are vulnerable.
IBM Connections is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to consume memory resources and cause a denial-of-service condition.
IBM Connections 3.0.1.1 and earlier, 4.0, 4.5 and 5.0 are vulnerable.
Exploit / POC
IBM Connections CVE-2015-7461 XML External Entity Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
IBM Connections CVE-2015-7461 XML External Entity Denial of Service Vulnerability
References:
References: