The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T12:47:32.833Z
Reserved: 2014-10-02T00:00:00
Link: CVE-2014-7296

No data.

Status : Deferred
Published: 2014-10-08T19:55:05.017
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-7296

No data.