CVE Database
/

CVE-2014-7296

Back to search

CVE-2014-7296

Published: Oct 8, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.

VendorProductVersions

n/a

n/a

affected
n/a

References

70240
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now