2 results (0.003 seconds)

CVSS: 9.0EPSS: 0%CPEs: 6EXPL: 0

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 119515. IBM WebSphere Cast Iron Solution 7.0.0 y 7.5.0.0 es vulnerable a una denegación de servicio, provocada por un error XML External Entity Injection (XXE) al procesar la información XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información altamente sensible o consumir todos los recursos de memoria disponibles. • http://www.ibm.com/support/docview.wss?uid=swg21998014 http://www.securityfocus.com/bid/98338 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 8.6EPSS: 0%CPEs: 6EXPL: 0

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 119516. IBM WebSphere Cast Iron Solution 7.0.0 y 7.5.0.0 es vulnerable a un ataque de interacción external con el servicio, provocado por la validación incorrecta de la entrada de datos suministrada por el usuario. • http://www.ibm.com/support/docview.wss?uid=swg21998014 http://www.securityfocus.com/bid/98337 • CWE-20: Improper Input Validation •