Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:ibm:security_appscan:8.7.0.0:*:*:*:standard:*:*:*", "matchCriteriaId": "A37494E7-92CC-46D2-96E4-5A44C47A8280", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:8.7.0.1:*:*:*:standard:*:*:*", "matchCriteriaId": "A8EB6F2E-1A29-417C-A28E-865324FFF7FC", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:8.8.0.0:*:*:*:standard:*:*:*", "matchCriteriaId": "869C4237-8FB5-4433-AA51-9FDE2AF9B1CC", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:9.0.0.0:*:*:*:standard:*:*:*", "matchCriteriaId": "E2C2DF51-B9ED-4F03-9FFB-FAE8E6308FAB", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:9.0.0.1:*:*:*:standard:*:*:*", "matchCriteriaId": "EA28F9E1-CEB9-4BBC-BAFC-1E9530C6BF55", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:9.0.1.0:*:*:*:standard:*:*:*", "matchCriteriaId": "E4819FF1-6E25-459B-B85B-4525856C5747", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:9.0.1.1:*:*:*:standard:*:*:*", "matchCriteriaId": "92EB3451-C14D-438C-AA9C-07DAB4845DA6", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:9.0.2.0:*:*:*:standard:*:*:*", "matchCriteriaId": "08E28D89-A868-4CFE-AD6C-B81E19C06BCC", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:9.0.2.1:*:*:*:standard:*:*:*", "matchCriteriaId": "8427A038-2159-4AB8-8403-B65510BC0A62", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:9.0.3.0:*:*:*:standard:*:*:*", "matchCriteriaId": "30DBA14E-B6E9-4EB2-8DFA-5176F2CC186F", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan:9.0.3.1:*:*:*:standard:*:*:*", "matchCriteriaId": "57AB9289-5671-472E-8C5B-183760169148", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."}, {"lang": "es", "value": "IBM Security AppScan Standard 8.7.x, 8.8.x y 9.x en versiones anteriores a 9.0.3.2 y Security AppScan Enterprise permiten a usuarios remotos autenticados leer archivos arbitrarios a trav\u00e9s de un documento XML que contiene una declaraci\u00f3n de entidad externa en conjunci\u00f3n con una referencia de entidad, relacionado con un problema XML External Entity (XXE)."}], "evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/611.html\">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')</a>", "id": "CVE-2016-0288", "lastModified": "2025-04-12T10:46:40.837", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "NONE", "baseScore": 4.0, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N", "version": "2.0"}, "exploitabilityScore": 8.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV30": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.0"}, "exploitabilityScore": 2.8, "impactScore": 3.6, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2016-06-01T15:59:00.233", "references": [{"source": "psirt@us.ibm.com", "tags": ["Vendor Advisory"], "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21980055"}, {"source": "psirt@us.ibm.com", "url": "http://www.securitytracker.com/id/1035927"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21980055"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securitytracker.com/id/1035927"}], "sourceIdentifier": "psirt@us.ibm.com", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "NVD-CWE-Other"}], "source": "nvd@nist.gov", "type": "Primary"}]}