CVE-2016-3039: IBM Traveler

High severity, CVSS 8.1. EPSS: 2.1% chance of exploitation in the next 30 days.

IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected products

  • IBM Traveler: version 8.5.3 only; version 9.0 only; version 9.0.1 only

Published 2016-07-17. Last modified 2026-06-17.