First published: Thu Jan 15 2015(Updated: )
XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Data Virtualization | <=6.0.0 | |
Odata4j Project Odata4j |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.