CVE-2014-7839

CVSS v2.0 6.4 (Medium)
64% Progress
EPSS 0.94 % (83th)
0.94% Progress
Affected Products 1
Advisories 1

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2014-11-25 15:59:01
(9 years ago)
Updated Date
2015-04-23 01:59:36
(9 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Redhat Resteasy 2.3.7 cpe:2.3:a:redhat:resteasy:2.3.7
  Redhat Resteasy 3.0.9 cpe:2.3:a:redhat:resteasy:3.0.9
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...