Overview
Granite Data Services version 3.1.1-SNAPSHOT AMF framework is vulnerable to XML external entity (XXE) attack that may be leveraged to expose sensitive data on the host..
Description
| CWE-611 - Improper Restriction of XML External Entity Reference ('XXE') - CVE-2016-2340 | 
Impact
| A vulnerable server would allow a remote user access to sensitive data or cause a denial of service. | 
Solution
| The CERT/CC is currently unaware of a practical solution to this problem. | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 4.3 | AV:L/AC:L/Au:S/C:P/I:P/A:P | 
| Temporal | 3.5 | E:POC/RL:ND/RC:UC | 
| Environmental | 1.4 | CDP:LM/TD:L/CR:M/IR:M/AR:M | 
References
Acknowledgements
Thanks to Travis Emmert for reporting this vulnerability.
This document was written by Kyle O'Meara.
Other Information
| CVE IDs: | CVE-2016-2340 | 
| Date Public: | 2016-03-24 | 
| Date First Published: | 2016-03-24 | 
| Date Last Updated: | 2016-03-24 14:45 UTC | 
| Document Revision: | 30 |