Lucene search

K
f5F5F5:K70191975
HistorySep 15, 2016 - 12:00 a.m.

K70191975 : Apache Xerces vulnerability CVE-2016-4463

2016-09-1500:00:00
my.f5.com
20

7.3 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

81.1%

Security Advisory Description

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD. (CVE-2016-4463)
Impact
An attacker requires privileged access to a dynamically generated XML file to exploit one of the affected components of the BIG-IP APM system. Additionally, an attacker must have access to a privileged user in order to download a malformed XML file on the system to trigger the exploit.