Lucene search

K
ibmIBM6A37DE59FED34A42ED9E99ED9CC903C36AD65067B000D8B025C49EC5C8ECA0F6
HistoryJul 30, 2021 - 5:03 a.m.

Security Bulletin: Castor Vulnerability Affects IBM Control Center (CVE-2014-3004)

2021-07-3005:03:07
www.ibm.com
11
castor vulnerability
ibm control center
xml external entity injection
remote attacker
sensitive information
vulnerabilities
fix central.

EPSS

0.016

Percentile

87.6%

Summary

Castor Library could allow a remote attacker to obtain sensitive information, caused by an XML External Entity Injection (XXE) error when processing XML data.

Vulnerability Details

CVEID:CVE-2014-3004
**DESCRIPTION:**Castor Library could allow a remote attacker to obtain sensitive information, caused by an XML External Entity Injection (XXE) error when processing XML data. By sending specially-crafted XML data, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/93519 for the current score.
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Control Center 6.2.0.0

Remediation/Fixes

Product

|

VRMF

|

iFix

|

Remediation

β€”|β€”|β€”|β€”

IBM Control Center

|

6.2.0.0

|

iFix09

|

Fix Central - 6.2.0.0

Workarounds and Mitigations

None

EPSS

0.016

Percentile

87.6%

Related for 6A37DE59FED34A42ED9E99ED9CC903C36AD65067B000D8B025C49EC5C8ECA0F6