CVE-2014-7296: Code Injection
Published Oct 8, 2014
·Updated
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURESECUREPROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.
Affected Software
1 affected component
eng SpagoBI=5.0
Event History
Oct 8, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7296?
CVE-2014-7296 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2014-7296?
To fix CVE-2014-7296, ensure that the accessibility engine's configuration sets FEATURE_SECURE_PROCESSING to true.
3
What software is affected by CVE-2014-7296?
CVE-2014-7296 affects SpagoBI version 5.0.0.
4
What type of attacks can CVE-2014-7296 facilitate?
CVE-2014-7296 can facilitate remote code execution attacks through crafted XSL documents.
5
Who can exploit CVE-2014-7296?
CVE-2014-7296 can be exploited by remote authenticated users.