ZeroHour

CVE-2016-3027

CVSS 3.0
6.5 medium
EPSS
1%p69
Published
()
Modified
Description

IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.

Vendors
ibm
Products
security access manager 9.0 firmware, security access manager for mobile 8.0 firmware, security access manager for web 8.0 firmware
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.