Overview
Granite Data Services version 3.1.1-SNAPSHOT AMF framework is vulnerable to XML external entity (XXE) attack that may be leveraged to expose sensitive data on the host..
Description
CWE-611 - Improper Restriction of XML External Entity Reference ('XXE') - CVE-2016-2340 |
Impact
A vulnerable server would allow a remote user access to sensitive data or cause a denial of service. |
Solution
The CERT/CC is currently unaware of a practical solution to this problem. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.3 | AV:L/AC:L/Au:S/C:P/I:P/A:P |
Temporal | 3.5 | E:POC/RL:ND/RC:UC |
Environmental | 1.4 | CDP:LM/TD:L/CR:M/IR:M/AR:M |
References
Acknowledgements
Thanks to Travis Emmert for reporting this vulnerability.
This document was written by Kyle O'Meara.
Other Information
CVE IDs: | CVE-2016-2340 |
Date Public: | 2016-03-24 |
Date First Published: | 2016-03-24 |
Date Last Updated: | 2016-03-24 14:45 UTC |
Document Revision: | 30 |