Логотип exploitDog
bind:CVE-2014-3490
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-3490

Количество 4

Количество 4

redhat логотип

CVE-2014-3490

около 11 лет назад

RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-3490

около 11 лет назад

RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-qjpq-5pq3-43rr

больше 3 лет назад

Incorrect Privilege Assignment in RESTEasy

EPSS: Низкий
oracle-oval логотип

ELSA-2014-1011

около 11 лет назад

ELSA-2014-1011: resteasy-base security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-3490

RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.

CVSS2: 5
5%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-3490

RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.

CVSS2: 7.5
5%
Низкий
около 11 лет назад
github логотип
GHSA-qjpq-5pq3-43rr

Incorrect Privilege Assignment in RESTEasy

5%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2014-1011

ELSA-2014-1011: resteasy-base security update (MODERATE)

около 11 лет назад

Уязвимостей на страницу