PT-2014-6448 · Sos Berlin · Jobscheduler
Oliver Haufe
·
Published
2014-09-23
·
Updated
2018-10-09
·
CVE-2014-5392
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
JobScheduler versions prior to 1.6.4246
JobScheduler versions 7.x prior to 1.7.4241
Description
The issue allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference.
Recommendations
For JobScheduler versions prior to 1.6.4246, update to version 1.6.4246 or later.
For JobScheduler versions 7.x prior to 1.7.4241, update to version 1.7.4241 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jobscheduler