CVE-2017-14101
Last modified
CVE-2017-14101 is a vulnerability of currently unknown severity. A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP request to the vulnerable service allows for arbitrary file read access to the local file system as well as the transmittal of the application service's account hashed credentials to a remote attacker.. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP request to the vulnerable service allows for arbitrary file read access to the local file system as well as the transmittal of the application service's account hashed credentials to a remote attacker.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Changehealthcare | Conserus Image Repository | 2.1.1.105 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14101?
How severe is CVE-2017-14101?
How do I fix CVE-2017-14101?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14095A vulnerability in Trend Micro Smart Protection Server (Stan…
- CVE-2017-14096A stored cross site scripting (XSS) vulnerability in Trend M…
- CVE-2017-14097An improper access control vulnerability in Trend Micro Smar…
- CVE-2017-14098In the pjsip channel driver (res_pjsip) in Asterisk 13.x bef…
- CVE-2017-14099In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 1…
- CVE-2017-14100In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14…
- CVE-2017-14102MIMEDefang 2.80 and earlier creates a PID file after droppin…
- CVE-2017-14103The ReadJNGImage and ReadOneJNGImage functions in coders/png…
- CVE-2017-14105HiveManager Classic through 8.1r1 allows arbitrary JSP code …
- CVE-2017-14106The tcp_disconnect function in net/ipv4/tcp.c in the Linux k…
- CVE-2017-14107The _zip_read_eocd64 function in zip_open.c in libzip before…6.5
- CVE-2017-14108libgedit.a in GNOME gedit through 3.22.1 allows remote attac…
Are you affected by CVE-2017-14101?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
