CVE-2014-3630: XEE
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-3630?
CVE-2014-3630 is an XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5.
How severe is CVE-2014-3630?
CVE-2014-3630 has a severity score of 9.8 (critical).
Which software is affected by CVE-2014-3630?
Lightbend Play Framework versions 2.2.0 to 2.2.2 and Play Framework versions 2.2.0 to 2.2.5 are affected by CVE-2014-3630.
How can CVE-2014-3630 be exploited?
CVE-2014-3630 can be exploited by remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Are there any references related to CVE-2014-3630?
Yes, you can find more information about CVE-2014-3630 in the following references: 1. https://groups.google.com/forum/#!msg/play-framework/7uNX_ImTW08/AogWSjsTAyQJ 2. https://groups.google.com/forum/#!topic/play-framework/WdbFvemsFDQ 3. https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf