CVE-2014-8316

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/10/2014
Last modified:
12/04/2025

Description

XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remote attackers to read arbitrary files via the xmlParameter parameter in an explorationSpaceUpdate request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:businessobjects_explorer:14.0.5:*:*:*:*:*:*:*