CVE-2014-3004: XEE
Published Jun 11, 2014
·Updated
Castor Library could allow a remote attacker to obtain sensitive information, caused by an XML External Entity Injection (XXE) error when processing XML data. By sending specially-crafted XML data, an attacker could exploit this vulnerability to obtain sensitive information.
Other sources
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.
Affected Software
5 affected components
Castor Project Castor<=1.3.2
Castor Project Castor=1.3
Castor Project Castor=1.3.1
openSUSE openSUSE=13.1
Opensuse Project Opensuse=12.3
Event History
Jun 11, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Aug 3, 2024
Data Sourced
via IBM·05:47 PM
DescriptionSeverityAffected Software