| Detector: | Tikanga |
| Target: | project ' odata4j ' version0.6 |
| Misuse: | misuse ' SV_CVE_14_0171 ' |
| Tags: |
Details about the known misuse from the MUBench dataset.
| Description: | XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint. |
| Fix Description: | (see diff) |
| Violations: |
|
| In File: | org/odata4j/stax2/staximpl/StaxXMLFactoryProvider2.java |
| In Method: | newXMLInputFactory2() |
| Code with Misuse: |
|