{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-15T12:38:52.215","vulnerabilities":[{"cve":{"id":"CVE-2014-5392","sourceIdentifier":"cve@mitre.org","published":"2014-09-23T15:55:08.167","lastModified":"2025-04-12T10:46:40.837","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference."},{"lang":"es","value":"Vulnerabilidad XML External Entity (XXE) en JobScheduler anterior a 1.6.4246 y 7.x anterior a 1.7.4241 permite a atacantes remotos causar una denegación de servicio y leer archivos arbitrarios o directorios a través de una solicitud que contiene una declaración de entidad externa XML en conjunto con una referencia de entidad."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N\/AC:M\/Au:N\/C:P\/I:N\/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sos:jobscheduler:*:*:*:*:*:*:*:*","versionEndIncluding":"1.6.4131","matchCriteriaId":"04063BAB-E033-4FCB-9894-11974EC85316"},{"vulnerable":true,"criteria":"cpe:2.3:a:sos:jobscheduler:1.6.4014:*:*:*:*:*:*:*","matchCriteriaId":"D2B9B1EE-3C37-4B0C-9AC0-7B479558CED9"},{"vulnerable":true,"criteria":"cpe:2.3:a:sos:jobscheduler:1.6.4043:*:*:*:*:*:*:*","matchCriteriaId":"3467B07E-0498-4B36-BCC3-DC7EC385D06D"},{"vulnerable":true,"criteria":"cpe:2.3:a:sos:jobscheduler:1.7.4177:*:*:*:*:*:*:*","matchCriteriaId":"9BEA7100-9FA7-4F66-9DA9-AD52AD487217"},{"vulnerable":true,"criteria":"cpe:2.3:a:sos:jobscheduler:1.7.4189:*:*:*:*:*:*:*","matchCriteriaId":"337165FD-1F47-4493-89F6-73834E436C63"}]}]}],"references":[{"url":"http:\/\/packetstormsecurity.com\/files\/128181\/JobScheduler-XML-eXternal-Entity-Injection.html","source":"cve@mitre.org","tags":["Patch"]},{"url":"http:\/\/www.christian-schneider.net\/advisories\/CVE-2014-5392.txt","source":"cve@mitre.org","tags":["Patch"]},{"url":"http:\/\/www.securityfocus.com\/archive\/1\/533374\/100\/0\/threaded","source":"cve@mitre.org"},{"url":"http:\/\/www.sos-berlin.com\/modules\/news\/article.php?storyid=73","source":"cve@mitre.org","tags":["Patch"]},{"url":"https:\/\/change.sos-berlin.com\/browse\/JS-1204","source":"cve@mitre.org"},{"url":"http:\/\/packetstormsecurity.com\/files\/128181\/JobScheduler-XML-eXternal-Entity-Injection.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http:\/\/www.christian-schneider.net\/advisories\/CVE-2014-5392.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http:\/\/www.securityfocus.com\/archive\/1\/533374\/100\/0\/threaded","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http:\/\/www.sos-berlin.com\/modules\/news\/article.php?storyid=73","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https:\/\/change.sos-berlin.com\/browse\/JS-1204","source":"af854a3a-2127-422b-91ae-364da2661108"}],"evaluatorComment":"<a href=\"http:\/\/cwe.mitre.org\/data\/definitions\/611.html\" target=\"_blank\">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')<\/a>"}}]}