PT-2014-7888 · Ow2 · Spagobi

Published

2014-10-08

·

Updated

2014-10-10

·

CVE-2014-7296

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SpagoBI version 5.0.0
Description The issue concerns the accessibility engine in SpagoBI, where the default configuration does not set FEATURE SECURE PROCESSING. This allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.
Recommendations For SpagoBI version 5.0.0, consider setting the FEATURE SECURE PROCESSING feature to prevent the execution of arbitrary Java code. As a temporary workaround, restrict access to the accessibility engine until a proper configuration or patch is available.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7296

Affected Products

Spagobi