CVE-2014-4769

IBM WebSphere Commerce <6.0.0.11 & 7.0.0.8 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

References (5)

Core 5
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1JR50553
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1JR49897
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/94836
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685464
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70872

Scores

EPSS 0.0118
EPSS Percentile 64.4%

Details

Status published
Products (21)
ibm/websphere_commerce 6.0.0.0
ibm/websphere_commerce 6.0.0.1
ibm/websphere_commerce 6.0.0.2
ibm/websphere_commerce 6.0.0.3
ibm/websphere_commerce 6.0.0.4
ibm/websphere_commerce 6.0.0.5
ibm/websphere_commerce 6.0.0.6
ibm/websphere_commerce 6.0.0.7
ibm/websphere_commerce 6.0.0.8
ibm/websphere_commerce 6.0.0.9
... and 11 more
Published Nov 05, 2014
Tracked Since Feb 18, 2026