CVE-2016-2340
MEDIUMGraniteds Granite Data Services - Denial of Service
Title source: ruleDescription
The AMF framework in Granite Data Services 3.1.1-SNAPSHOT allows remote authenticated users to read arbitrary files, send TCP requests to intranet servers, or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Scores
CVSS v3
5.4
EPSS
0.0029
EPSS Percentile
52.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Classification
Status
draft
Affected Products (1)
graniteds/granite_data_services
Timeline
Published
Mar 25, 2016
Tracked Since
Feb 18, 2026