PT-2014-3514 · Red Hat · Red Hat Jboss Data Virtualization+1

David Jorm

·

Publicado

2014-09-30

·

Atualizado

2017-08-29

·

CVE-2014-0170

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Teiid versions prior to 8.4.3 Teiid versions prior to 8.7 Red Hat JBoss Data Virtualization 6.0.0 before patch 3
Description The issue allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue. This means that an attacker can potentially access sensitive files on the system by exploiting this weakness.
Recommendations For Teiid versions prior to 8.4.3, update to version 8.4.3 or later. For Teiid versions prior to 8.7, update to version 8.7 or later. For Red Hat JBoss Data Virtualization 6.0.0, apply patch 3 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2014-0170

Produtos afetados

Red Hat Jboss Data Virtualization
Teiid