![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2014-6166 |
Description: | The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.806888 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-6166 AIX APAR: PI25310 http://www-01.ibm.com/support/docview.wss?uid=swg1PI25310 AIX APAR: PI28632 http://www-01.ibm.com/support/docview.wss?uid=swg1PI28632 XForce ISS Database: ibm-websphere-cve20146166-info-disc(97746) https://exchange.xforce.ibmcloud.com/vulnerabilities/97746 |