PT-2014-3514 · Red Hat · Red Hat Jboss Data Virtualization+1

David Jorm

·

Published

2014-09-30

·

Updated

2017-08-29

·

CVE-2014-0170

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Teiid versions prior to 8.4.3 Teiid versions prior to 8.7 Red Hat JBoss Data Virtualization 6.0.0 before patch 3
Description The issue allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue. This means that an attacker can potentially access sensitive files on the system by exploiting this weakness.
Recommendations For Teiid versions prior to 8.4.3, update to version 8.4.3 or later. For Teiid versions prior to 8.7, update to version 8.7 or later. For Red Hat JBoss Data Virtualization 6.0.0, apply patch 3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-0170

Affected Products

Red Hat Jboss Data Virtualization
Teiid