Direct Web Remoting CVE-2014-5325 XML External Entity Injection Vulnerability
BID:71093
Info
Direct Web Remoting CVE-2014-5325 XML External Entity Injection Vulnerability
| Bugtraq ID: | 71093 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-5325 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2014 12:00AM |
| Updated: | Jul 15 2015 12:25AM |
| Credit: | Takeshi Terada of Mitsui Bussan Secure Directions |
| Vulnerable: |
IBM Rational Change 5.3 3 |
| Not Vulnerable: | |
Discussion
Direct Web Remoting CVE-2014-5325 XML External Entity Injection Vulnerability
Direct Web Remoting is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Direct Web Remoting is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Exploit / POC
Direct Web Remoting CVE-2014-5325 XML External Entity Injection Vulnerability
An attacker can exploit this issue using readily available tools..
An attacker can exploit this issue using readily available tools..
Solution / Fix
Direct Web Remoting CVE-2014-5325 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Direct Web Remoting CVE-2014-5325 XML External Entity Injection Vulnerability
References:
References: