CVE-2014-0171
15.01.2015, 15:59
XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jboss_data_virtualization | 𝑥 ≤ 6.0.0 |
odata4j_project | odata4j | - |
𝑥
= Vulnerable software versions