XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint.
| Software | From | Fixed in |
|---|---|---|
| redhat / jboss_data_virtualization | - | 6.0.0.x |