Vulnerability Bulletins |
Cisco Information Server XML Parser Denial of Service Vulnerability |
|
| Affected software | Cisco |
|
A vulnerability in the default configuration of the XML parser component of Cisco Information Server (CIS) could allow an unauthenticated, remote attacker to access sensitive data or cause excessive consumption of system resources, which could cause a denial of service (DoS) condition on a targeted system.The vulnerability is due to improper handling of XML External Entities (XXE) by the affected software when the software parses XML files. An attacker could exploit this vulnerability by More info: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160428-cis?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Information%20Server%20XML%20Parser%20Denial%20of%20Service%20Vulnerab |
|






