4

CVE-2014-4769

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Commerce Version 6.0.0.0
Ibm ≫ Websphere Commerce Version 6.0.0.1
Ibm ≫ Websphere Commerce Version 6.0.0.2
Ibm ≫ Websphere Commerce Version 6.0.0.3
Ibm ≫ Websphere Commerce Version 6.0.0.4
Ibm ≫ Websphere Commerce Version 6.0.0.5
Ibm ≫ Websphere Commerce Version 6.0.0.6
Ibm ≫ Websphere Commerce Version 6.0.0.7
Ibm ≫ Websphere Commerce Version 6.0.0.8
Ibm ≫ Websphere Commerce Version 6.0.0.9
Ibm ≫ Websphere Commerce Version 6.0.0.10
Ibm ≫ Websphere Commerce Version 6.0.0.11
Ibm ≫ Websphere Commerce Version 7.0
Ibm ≫ Websphere Commerce Version 7.0.0.1
Ibm ≫ Websphere Commerce Version 7.0.0.2
Ibm ≫ Websphere Commerce Version 7.0.0.3
Ibm ≫ Websphere Commerce Version 7.0.0.4
Ibm ≫ Websphere Commerce Version 7.0.0.5
Ibm ≫ Websphere Commerce Version 7.0.0.6
Ibm ≫ Websphere Commerce Version 7.0.0.7
Ibm ≫ Websphere Commerce Version 7.0.0.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.18% 0.636
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www-01.ibm.com/support/docview.wss?uid=swg1JR49897
http://www-01.ibm.com/support/docview.wss?uid=swg1JR50553
http://www-01.ibm.com/support/docview.wss?uid=swg21685464
Vendor Advisory
http://www.securityfocus.com/bid/70872
https://exchange.xforce.ibmcloud.com/vulnerabilities/94836