CVE-2014-5392

critical

Description

XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference.

References

https://change.sos-berlin.com/browse/JS-1204

http://www.sos-berlin.com/modules/news/article.php?storyid=73

http://www.securityfocus.com/archive/1/533374/100/0/threaded

http://www.christian-schneider.net/advisories/CVE-2014-5392.txt

http://packetstormsecurity.com/files/128181/JobScheduler-XML-eXternal-Entity-Injection.html

Details

Source: Mitre, NVD

Published: 2014-09-23

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Severity: Critical

EPSS

EPSS: 0.0091