CVE-2016-0254
CVE-2016-0254
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
07 Jun 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vulnerability to consume all available CPU resources and cause a denial of service. IBM X-Force ID: 110563.
Affected products
IBM · Cognos Business IntelligenceWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →