CVE-2014-6166
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
El servicio Communications Enabled Applications (CEA) en IBM WebSphere Application Server 8.0.x anterior a 8.0.0.10 y 8.5.x anterior a 8.5.5.4 y Feature Pack for CEA 1.x anterior a 1.0.0.15 permite a atacantes remotos a leer archivos arbitrarios mediante una declaraciĆ³n de identidad XML externa junto con una referencia a una entidad, relacionado con el error XML External Entity (XXE).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-09-02 CVE Reserved
- 2014-12-18 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/97746 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1PI25310 | 2017-09-08 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI28632 | 2017-09-08 | |
http://www-01.ibm.com/support/docview.wss?uid=swg21690185 | 2017-09-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.0 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.1 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.2 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.3 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.4 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.5 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.6 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.6" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.7 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.8 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.8" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.0.0.9 Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.9" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.5.0.0 Search vendor "Ibm" for product "Websphere Application Server" and version "8.5.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.5.0.1 Search vendor "Ibm" for product "Websphere Application Server" and version "8.5.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.5.0.2 Search vendor "Ibm" for product "Websphere Application Server" and version "8.5.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.5.5.0 Search vendor "Ibm" for product "Websphere Application Server" and version "8.5.5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.5.5.1 Search vendor "Ibm" for product "Websphere Application Server" and version "8.5.5.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.5.5.2 Search vendor "Ibm" for product "Websphere Application Server" and version "8.5.5.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 8.5.5.3 Search vendor "Ibm" for product "Websphere Application Server" and version "8.5.5.3" | - |
Affected
|