PT-2014-3514 · Red Hat · Red Hat Jboss Data Virtualization+1
David Jorm
·
Published
2014-09-30
·
Updated
2017-08-29
·
CVE-2014-0170
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Teiid versions prior to 8.4.3
Teiid versions prior to 8.7
Red Hat JBoss Data Virtualization 6.0.0 before patch 3
Description
The issue allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue. This means that an attacker can potentially access sensitive files on the system by exploiting this weakness.
Recommendations
For Teiid versions prior to 8.4.3, update to version 8.4.3 or later.
For Teiid versions prior to 8.7, update to version 8.7 or later.
For Red Hat JBoss Data Virtualization 6.0.0, apply patch 3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat Jboss Data Virtualization
Teiid