CVE-2014-3630
 
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Vulnerabilidad de XEE (XML External Entity) en la funcionalidad de procesamiento de Java XML en Play, en versiones anteriores a la 2.2.6 y versiones 2.3.x anteriores a la 2.3.5, podrÃa permitir a atacantes remotos leer archivos arbitrarios, provocar una denegación de servicio (DoS) o causar otro tipo de impacto no especificado mediante datos XML manipulados.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-05-14 CVE Reserved
- 2017-12-29 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (4)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://playframework.com/security/vulnerability/CVE-2014-3630-XmlExternalEntity | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.2.0 Search vendor "Lightbend" for product "Play Framework" and version "2.2.0" | - |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.2.0 Search vendor "Lightbend" for product "Play Framework" and version "2.2.0" | milestone1 |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.2.0 Search vendor "Lightbend" for product "Play Framework" and version "2.2.0" | milestone2 |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.2.0 Search vendor "Lightbend" for product "Play Framework" and version "2.2.0" | milestone3 |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.2.1 Search vendor "Lightbend" for product "Play Framework" and version "2.2.1" | - |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.2.2 Search vendor "Lightbend" for product "Play Framework" and version "2.2.2" | - |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.3.0 Search vendor "Lightbend" for product "Play Framework" and version "2.3.0" | - |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.3.0 Search vendor "Lightbend" for product "Play Framework" and version "2.3.0" | rc1 |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.3.0 Search vendor "Lightbend" for product "Play Framework" and version "2.3.0" | rc2 |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.3.1 Search vendor "Lightbend" for product "Play Framework" and version "2.3.1" | - |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.3.2 Search vendor "Lightbend" for product "Play Framework" and version "2.3.2" | - |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.3.2 Search vendor "Lightbend" for product "Play Framework" and version "2.3.2" | rc1 |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.3.2 Search vendor "Lightbend" for product "Play Framework" and version "2.3.2" | rc2 |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.3.3 Search vendor "Lightbend" for product "Play Framework" and version "2.3.3" | - |
Affected
| ||||||
Lightbend Search vendor "Lightbend" | Play Framework Search vendor "Lightbend" for product "Play Framework" | 2.3.4 Search vendor "Lightbend" for product "Play Framework" and version "2.3.4" | - |
Affected
| ||||||
Playframework Search vendor "Playframework" | Play Framework Search vendor "Playframework" for product "Play Framework" | 2.2.0 Search vendor "Playframework" for product "Play Framework" and version "2.2.0" | rc1 |
Affected
| ||||||
Playframework Search vendor "Playframework" | Play Framework Search vendor "Playframework" for product "Play Framework" | 2.2.1 Search vendor "Playframework" for product "Play Framework" and version "2.2.1" | rc1 |
Affected
| ||||||
Playframework Search vendor "Playframework" | Play Framework Search vendor "Playframework" for product "Play Framework" | 2.2.2 Search vendor "Playframework" for product "Play Framework" and version "2.2.2" | rc1 |
Affected
| ||||||
Playframework Search vendor "Playframework" | Play Framework Search vendor "Playframework" for product "Play Framework" | 2.2.2 Search vendor "Playframework" for product "Play Framework" and version "2.2.2" | rc2 |
Affected
| ||||||
Playframework Search vendor "Playframework" | Play Framework Search vendor "Playframework" for product "Play Framework" | 2.2.2 Search vendor "Playframework" for product "Play Framework" and version "2.2.2" | rc3 |
Affected
| ||||||
Playframework Search vendor "Playframework" | Play Framework Search vendor "Playframework" for product "Play Framework" | 2.2.2 Search vendor "Playframework" for product "Play Framework" and version "2.2.2" | rc4 |
Affected
| ||||||
Playframework Search vendor "Playframework" | Play Framework Search vendor "Playframework" for product "Play Framework" | 2.2.3 Search vendor "Playframework" for product "Play Framework" and version "2.2.3" | - |
Affected
| ||||||
Playframework Search vendor "Playframework" | Play Framework Search vendor "Playframework" for product "Play Framework" | 2.2.4 Search vendor "Playframework" for product "Play Framework" and version "2.2.4" | - |
Affected
| ||||||
Playframework Search vendor "Playframework" | Play Framework Search vendor "Playframework" for product "Play Framework" | 2.2.5 Search vendor "Playframework" for product "Play Framework" and version "2.2.5" | - |
Affected
|