Vulnerability Bulletins |
IBM Security Bulletin: XML External Entities Injection Vulnerability in IBM Traveler (CVE-2016-3039) |
|
| Affected software | IBM |
|
IBM Traveler is vulnerable to a denial of service caused by an XML External Entity Injection (XXE) error when processing XML data.CVE(s): CVE-2016-3039Affected product(s) and affected version(s): IBM Traveler 8.5.3 IBM Traveler 9.0 IBM Traveler 9.0.1 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21985858X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/114629 More info: https://www.ibm.com/blogs/psirt/ibm-security-bulletin-xml-external-entities-injection-vulnerability-in-ibm-traveler-cve-2016-3039/ |
|






