CVE-2016-2340

The AMF framework in Granite Data Services 3.1.1-SNAPSHOT allows remote authenticated users to read arbitrary files, send TCP requests to intranet servers, or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References
Link Resource
http://www.kb.cert.org/vuls/id/279472 Patch Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/85426
Configurations

Configuration 1 (hide)

cpe:2.3:a:graniteds:granite_data_services:3.1.1-snapshot:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-03-25 21:59

Updated : 2024-02-04 18:53


NVD link : CVE-2016-2340

Mitre link : CVE-2016-2340

CVE.ORG link : CVE-2016-2340


JSON object : View

Products Affected

graniteds

  • granite_data_services