EMC Cloud Tiering Appliance (CTA) XML External Entity Injection vulnerability
BID:66547
Info
EMC Cloud Tiering Appliance (CTA) XML External Entity Injection vulnerability
| Bugtraq ID: | 66547 |
| Class: | Design Error |
| CVE: |
CVE-2014-0644 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2014 12:00AM |
| Updated: | Apr 17 2014 12:40AM |
| Credit: | Brandon Perry |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
EMC Cloud Tiering Appliance (CTA) XML External Entity Injection vulnerability
EMC Cloud Tiering Appliance (CTA) is prone to XML External Entity injection vulnerability.
Successfully exploiting this issue may allow an attacker to gain access to sensitive information; this may aid in further attacks.
EMC Cloud Tiering Appliance (CTA) 10.0 is vulnerable; other versions may also be affected.
EMC Cloud Tiering Appliance (CTA) is prone to XML External Entity injection vulnerability.
Successfully exploiting this issue may allow an attacker to gain access to sensitive information; this may aid in further attacks.
EMC Cloud Tiering Appliance (CTA) 10.0 is vulnerable; other versions may also be affected.
Exploit / POC
EMC Cloud Tiering Appliance (CTA) XML External Entity Injection vulnerability
An attacker can exploit this issue using readily available tools. The following metasploit module is available:
An attacker can exploit this issue using readily available tools. The following metasploit module is available:
Solution / Fix
EMC Cloud Tiering Appliance (CTA) XML External Entity Injection vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.