Vulnerability Bulletins

IBM Security Bulletin: IBM InfoSphere Information Governance Catalog is vulnerable to XXE Injection Attack (CVE-2016-0250)

   
Affected software IBM
 
IBM InfoSphere Information Governance Catalog could allow a remote authenticated attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service. CVE(s): CVE-2016-0250Affected product(s) and affected version(s):The following product, running on all supported platforms, is affected: IBM InfoSphere Information

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_infosphere_information_governance_catalog_is_vulnerable_to_xxe_injection_attack_cve_2016_0250?lang=en_us