Vulnerability Bulletins

IBM Security Bulletin: Vulnerability with WebSphere Commerce XML External Entity (XXE) Processing (CVE-2015-0133)

   
Affected software IBM
 
A vulnerability in IBM WebSphere Commerce XML External Entity (XXE) processing could allow a remote attacker to obtain sensitive information. CVE(s): CVE-2015-0133 Affected product(s) and affected version(s): WebSphere Commerce V7.0 Feature Pack 4 - Feature Pack 8 The following versions are not affected: WebSphere Commerce V7.0 Feature Pack 1 - Feature Pack 3 WebSphere Commerce V6.0 Refer to the following reference URLs for remediation and additional vulnerability details: Source

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_with_websphere_commerce_xml_external_entity_xxe_processing_cve_2015_0133?lang=en_us