IBM AppScan Source 8.7 up to and including 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm appscan source 9.0.0.1 |
||
ibm appscan source 9.0.2 |
||
ibm appscan source 9.0.3.1 |
||
ibm appscan source 9.0.3.2 |
||
ibm appscan source 9.0.3.3 |
||
ibm appscan source 8.7 |
||
ibm appscan source 8.7.0.1 |
||
ibm appscan source 8.8 |
||
ibm appscan source 9.0 |
||
ibm appscan source 9.0.1 |
||
ibm appscan source 9.0.3 |