5
CVSSv2

CVE-2014-0171

Published: 15/01/2015 Updated: 26/03/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization prior to 6.0.0 patch 4, allows remote malicious users to read arbitrary files via a crafted request to a REST endpoint.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss data virtualization

odata4j project odata4j -

Vendor Advisories

It was found that Odata4j permitted XML eXternal Entity (XXE) attacks If a REST endpoint was deployed, a remote attacker could submit a request containing an external XML entity that, when resolved, allowed that attacker to read files on the application server in the context of the user running that server ...