CVE-2014-4769
IBM WebSphere Commerce <6.0.0.11 & 7.0.0.8 - Info Disclosure
Title source: llmDescription
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References (5)
Core 5
Core References
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1JR50553
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1JR49897
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/94836
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685464
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/70872
Scores
EPSS
0.0118
EPSS Percentile
64.4%
Details
Status
published
Products (21)
ibm/websphere_commerce
6.0.0.0
ibm/websphere_commerce
6.0.0.1
ibm/websphere_commerce
6.0.0.2
ibm/websphere_commerce
6.0.0.3
ibm/websphere_commerce
6.0.0.4
ibm/websphere_commerce
6.0.0.5
ibm/websphere_commerce
6.0.0.6
ibm/websphere_commerce
6.0.0.7
ibm/websphere_commerce
6.0.0.8
ibm/websphere_commerce
6.0.0.9
... and 11 more
Published
Nov 05, 2014
Tracked Since
Feb 18, 2026