← Back

CVE-2014-5392

nvd nist
Published: Sep 23, 2014Modified: May 6, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:P
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference.

Affected (5)

Products: Sos: Jobscheduler
1 product
Jobscheduler
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Sos
Up to 1.6.4131
Version 1.6.4014
Version 1.6.4043
Version 1.7.4177
Version 1.7.4189

Timeline

No history available yet.