Vulnerability Details CVE-2014-3630
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2014-3630
-
cpe:2.3:a:lightbend:play_framework:2.2.0
-
cpe:2.3:a:lightbend:play_framework:2.2.1
-
cpe:2.3:a:lightbend:play_framework:2.2.2
-
cpe:2.3:a:lightbend:play_framework:2.3.0
-
cpe:2.3:a:lightbend:play_framework:2.3.1
-
cpe:2.3:a:lightbend:play_framework:2.3.2
-
cpe:2.3:a:lightbend:play_framework:2.3.3
-
cpe:2.3:a:lightbend:play_framework:2.3.4
-
cpe:2.3:a:playframework:play_framework:2.2.0
-
cpe:2.3:a:playframework:play_framework:2.2.1
-
cpe:2.3:a:playframework:play_framework:2.2.2
-
cpe:2.3:a:playframework:play_framework:2.2.3
-
cpe:2.3:a:playframework:play_framework:2.2.4
-
cpe:2.3:a:playframework:play_framework:2.2.5