CVE-2016-2340

The AMF framework in Granite Data Services 3.1.1-SNAPSHOT allows remote authenticated users to read arbitrary files, send TCP requests to intranet servers, or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References
Link Resource
http://www.kb.cert.org/vuls/id/279472 Patch Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/85426
http://www.kb.cert.org/vuls/id/279472 Patch Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/85426
Configurations

Configuration 1 (hide)

cpe:2.3:a:graniteds:granite_data_services:3.1.1-snapshot:*:*:*:*:*:*:*

History

21 Nov 2024, 02:48

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/279472 - Patch, Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/279472 - Patch, Third Party Advisory, US Government Resource
References () http://www.securityfocus.com/bid/85426 - () http://www.securityfocus.com/bid/85426 -

Information

Published : 2016-03-25 21:59

Updated : 2024-11-21 02:48


NVD link : CVE-2016-2340

Mitre link : CVE-2016-2340

CVE.ORG link : CVE-2016-2340


JSON object : View

Products Affected

graniteds

  • granite_data_services