Unrated severityNVD Advisory· Published Jan 15, 2015· Updated May 6, 2026
CVE-2014-0171
CVE-2014-0171
Description
XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint.
Affected products
2- cpe:2.3:a:odata4j_project:odata4j:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_data_virtualization:*:*:*:*:*:*:*:*Range: <=6.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- issues.jboss.org/browse/TEIID-2911nvdExploit
- rhn.redhat.com/errata/RHSA-2015-0034.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.