« Volver al listado

CVE-2014-3630

Estado: ModificadaCrítica (9.8)—

XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-3630",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-29T22:29:00.363",
  "references": [
    {
      "url": "https://groups.google.com/forum/#%21msg/play-framework/7uNX_ImTW08/AogWSjsTAyQJ",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://groups.google.com/forum/#%21topic/play-framework/WdbFvemsFDQ",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://playframework.com/security/vulnerability/CVE-2014-3630-XmlExternalEntity",
      "tags": [
        "Issue Tracking",
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://groups.google.com/forum/#%21msg/play-framework/7uNX_ImTW08/AogWSjsTAyQJ",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://groups.google.com/forum/#%21topic/play-framework/WdbFvemsFDQ",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://playframework.com/security/vulnerability/CVE-2014-3630-XmlExternalEntity",
      "tags": [
        "Issue Tracking",
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de XEE (XML External Entity) en la funcionalidad de procesamiento de Java XML en Play, en versiones anteriores a la 2.2.6 y versiones 2.3.x anteriores a la 2.3.5, podría permitir a atacantes remotos leer archivos arbitrarios, provocar una denegación de servicio (DoS) o causar otro tipo de impacto no especificado mediante datos XML manipulados."
    }
  ],
  "lastModified": "2026-06-17T00:08:39.140",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.2.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F790A14D-13BD-4924-9B56-BB73D7AB9441"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.2.0:milestone1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63908B48-9D7B-47E1-9531-70AD5EF6351D"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.2.0:milestone2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31B193D1-A0A7-4707-85B3-450126229618"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.2.0:milestone3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0099803B-5FDB-41C2-A0AA-3C40B6A1174D"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.2.1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D0F9F7F-6BAA-4BFE-9EF6-5FDC89B5A100"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.2.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1ED49591-2830-4388-841E-BB774CE18E88"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.3.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE253560-BABE-4917-80AE-92BE1AE41F04"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.3.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "475F2D6C-A82A-4607-AEEA-EB16DC7F3EEB"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.3.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81BCC634-6424-4D53-AE78-F00782F290DF"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA9A457C-DA32-4094-9EF7-5DCBA4904CF0"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.3.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9075EEDA-8FC6-4CD6-9420-0125E7B9A001"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.3.2:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89244DD5-3EA1-471F-B678-A6921D17A804"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.3.2:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96B59DC4-58BB-424C-BEFD-DF7E43E39C21"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CEFD24F-A241-44A7-9C2D-128F5C5F69BF"
            },
            {
              "criteria": "cpe:2.3:a:lightbend:play_framework:2.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D286954C-BD26-4433-84D3-D0F37B61BB4A"
            },
            {
              "criteria": "cpe:2.3:a:playframework:play_framework:2.2.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6C36CCE-6B7B-4346-81B2-40ACE8F2EE63"
            },
            {
              "criteria": "cpe:2.3:a:playframework:play_framework:2.2.1:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36149A37-5BF7-41EC-AD65-34F5DAFFC64B"
            },
            {
              "criteria": "cpe:2.3:a:playframework:play_framework:2.2.2:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "407B15E5-5355-4AE0-98E1-26B7C60D77A0"
            },
            {
              "criteria": "cpe:2.3:a:playframework:play_framework:2.2.2:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28A72C43-6033-4E99-BF41-513E4C69E2D3"
            },
            {
              "criteria": "cpe:2.3:a:playframework:play_framework:2.2.2:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E54E70F-8F06-4558-B725-045B379D6279"
            },
            {
              "criteria": "cpe:2.3:a:playframework:play_framework:2.2.2:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8061B89-3B8D-4D38-9DA8-A52EC97CF966"
            },
            {
              "criteria": "cpe:2.3:a:playframework:play_framework:2.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D664F3EF-B07F-47BC-A9CF-6CD22CF73D98"
            },
            {
              "criteria": "cpe:2.3:a:playframework:play_framework:2.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C991464B-52D4-4F70-91CE-E5FFDFCC6DD6"
            },
            {
              "criteria": "cpe:2.3:a:playframework:play_framework:2.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EDCCE92-D85D-453B-B13B-52FC888F340A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}