Skip to main content

CVE-2014-5392

Severity Medium
Score 5.8/10

Summary

XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference.

  • MEDIUM
  • NETWORK
  • NONE
  • NONE
  • PARTIAL
  • PARTIAL

References

Advisory Timeline

  • Published