Arbitrary File Read Vulnerability in Odata4j

Arbitrary File Read Vulnerability in Odata4j

CVE-2014-0171 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint.

Learn more about our External Network Penetration Testing.