HIGH · 7.8

CVE-2014-0644

EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity re...

Vulnerability Description

EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, as demonstrated by reading the /etc/shadow file.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
EmcCloud Tiering Appliance Software10.0
EmcCloud Tiering Appliance-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0644?

CVE-2014-0644 is a vulnerability with a CVSS score of 7.8 (HIGH). EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity re...

How severe is CVE-2014-0644?

CVE-2014-0644 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0644?

Check the references section above for vendor advisories and patch information. Affected products include: Emc Cloud Tiering Appliance Software, Emc Cloud Tiering Appliance.