CVE-2016-3674: Infoleak
Last updated 22 August 2024
Other sources
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
XStream could allow a remote attacker to obtain sensitive information, caused by an error when processing XML external entities. By sending specially-crafted XML data, an attacker could exploit this vulnerability to obtain sensitive information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-3674?
CVE-2016-3674 is a vulnerability in XStream that allows remote attackers to read arbitrary files via a crafted XML document.
What causes CVE-2016-3674 vulnerability?
CVE-2016-3674 is caused by multiple XML external entity (XXE) vulnerabilities in the XStream drivers.
How can an attacker exploit CVE-2016-3674?
An attacker can exploit CVE-2016-3674 by sending a crafted XML document to the target system.
Which software versions are affected by CVE-2016-3674?
Versions up to and including 1.4.8 of XStream and up to version 3.0.0.2 of IBM GDE are affected by CVE-2016-3674.
What is the severity of CVE-2016-3674?
The severity of CVE-2016-3674 is high, with a CVSS score of 7.5.