IBM Security Bulletin: Multiple IBM InfoSphere Information Server components are vulnerable due to the following Castor Library vulnerability (CVE-2014-3004)

Castor Library could allow a remote attacker to obtain sensitive information in various IBM Information Server components. This is caused by an XML External Entity Injection (XXE) error when processing XML data. By sending specially-crafted XML data, an...



from IBM Product Security Incident Response Team http://ibm.co/1C0wij4