CVE-2014-0170: Medium severity red hat jboss data virtualization vulnerability
Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0170?
CVE-2014-0170 is considered a high severity vulnerability due to its potential for remote file access.
How do I fix CVE-2014-0170?
To fix CVE-2014-0170, update to Teiid version 8.4.3 or later, or Red Hat JBoss Data Virtualization 6.0.0 patch 3 or later.
What types of attacks can exploit CVE-2014-0170?
CVE-2014-0170 can be exploited through crafted requests to a REST endpoint to read arbitrary files.
Which versions are affected by CVE-2014-0170?
Versions of Teiid before 8.4.3 and 8.7, as well as Red Hat JBoss Data Virtualization 6.0.0 before patch 3, are affected by CVE-2014-0170.
What is the primary vulnerability related to CVE-2014-0170?
The primary vulnerability in CVE-2014-0170 is related to XML External Entity (XXE) vulnerabilities.