VYPR
High severity8.1NVD Advisory· Published Jul 17, 2016· Updated May 6, 2026

CVE-2016-3039

CVE-2016-3039

Description

IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected products

3
  • IBM/Traveler3 versions
    cpe:2.3:a:ibm:traveler:8.5.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ibm:traveler:8.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:traveler:9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:traveler:9.0.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.