CVE-2014-0170
published 2014-09-30CVE-2014-0170: Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted…
PriorityP432medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.96%
78.1th percentile
Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jboss | teiid | <= 8.6 | — |
| jboss | teiid | — | — |
| redhat | jboss_data_virtualization | <= 6.0.0 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Teiid: XML eXternal Entity (XXE) flaw in SQL/XML parsing
vendor_redhat·2014-09-23·CVSS 4.3
CVE-2014-0170 [MEDIUM] CWE-611 Teiid: XML eXternal Entity (XXE) flaw in SQL/XML parsing
Teiid: XML eXternal Entity (XXE) flaw in SQL/XML parsing
Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue.
It was found that Teiid SQL/XML permitted XML eXternal Entity (XXE) attacks. If a REST endpoint was deployed, a remote attacker could submit a request containing an external XML entity that, when resolved, allowed that attacker to read files on the application server in the context of the user running that server.
GHSA
GHSA-4ffv-mqcc-vgr9: Teiid before 8
ghsa_unreviewed·2022-05-17
CVE-2014-0170 [MEDIUM] GHSA-4ffv-mqcc-vgr9: Teiid before 8
Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-1284.htmlhttp://secunia.com/advisories/61530http://www.securitytracker.com/id/1030886https://exchange.xforce.ibmcloud.com/vulnerabilities/96192https://issues.jboss.org/browse/TEIID-2911http://rhn.redhat.com/errata/RHSA-2014-1284.htmlhttp://secunia.com/advisories/61530http://www.securitytracker.com/id/1030886https://exchange.xforce.ibmcloud.com/vulnerabilities/96192https://issues.jboss.org/browse/TEIID-2911
2014-09-30
Published