CVE-2016-3033: IBM Appscan Source

High severity, CVSS 8.1. EPSS: 1.4% chance of exploitation in the next 30 days.

IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected products

  • IBM Appscan Source: version 8.7 only; version 8.7.0.1 only; version 8.8 only; version 9.0 only; version 9.0.0.1 only; version 9.0.1 only; …

Published 2016-12-01. Last modified 2026-06-17.