Input validation error in WebSphere Portal - CVE-2016-0245
Published: February 29, 2016 / Updated: August 9, 2020
WebSphere Portal
Detailed vulnerability description
The vulnerability allows remote authenticated users to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can read arbitrary files or cause a denial of service via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.