PT-2013-5549 · Ibm · Ibm Filenet Business Process Framework

Published

2013-12-19

·

Updated

2017-08-29

·

CVE-2013-5452

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM FileNet Business Process Framework version 4.1.0
Description The issue allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Recommendations For IBM FileNet Business Process Framework version 4.1.0, consider restricting access to XML data processing to minimize the risk of exploitation, and apply any available patches or configuration changes as recommended by the vendor to address the XML External Entity issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5452

Affected Products

Ibm Filenet Business Process Framework