CVE-2016-2340

MEDIUM

Graniteds Granite Data Services - Denial of Service

Title source: rule

Description

The AMF framework in Granite Data Services 3.1.1-SNAPSHOT allows remote authenticated users to read arbitrary files, send TCP requests to intranet servers, or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Scores

CVSS v3 5.4
EPSS 0.0029
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Classification

Status draft

Affected Products (1)

graniteds/granite_data_services

Timeline

Published Mar 25, 2016
Tracked Since Feb 18, 2026