Page 3 of 11 results (0.004 seconds)

CVSS: 8.1EPSS: 0%CPEs: 7EXPL: 0

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM BigFix Inventory v9 es vulnerable a una denegación de servicio, provocada por un error XML Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información altamente sensible o consumir todos los recursos de memoria disponibles. • http://www.ibm.com/support/docview.wss?uid=swg21995013 http://www.securityfocus.com/bid/95141 • CWE-611: Improper Restriction of XML External Entity Reference •