{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "XML eXternal Entity (XXE) flaw",
    "tracking": {
      "current_release_date": "2026-08-11T14:05:13+00:00",
      "generator": {
        "date": "2026-08-11T14:05:13+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2014-3529",
      "initial_release_date": "2014-08-18T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:05:13+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Virtualization 3.4.0",
            "product": {
              "name": "Red Hat Enterprise Virtualization 3.4.0",
              "product_id": "rhev-m-3.4.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhev_v2v:2"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Virtualization 3.5.0",
            "product": {
              "name": "Red Hat Enterprise Virtualization 3.5.0",
              "product_id": "rhev-m-3.5.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhev_v2v:2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jasperreports-server-pro",
            "product": {
              "name": "jasperreports-server-pro",
              "product_id": "jasperreports-server-pro.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/jasperreports-server-pro?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jasperreports-server-pro.src as a component of Red Hat Enterprise Virtualization 3.5.0",
          "product_id": "rhev-m-3.5.z:jasperreports-server-pro.src"
        },
        "product_reference": "jasperreports-server-pro.src",
        "relates_to_product_reference": "rhev-m-3.5.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jasperreports-server-pro.src as a component of Red Hat Enterprise Virtualization 3.4.0",
          "product_id": "rhev-m-3.4.z:jasperreports-server-pro.src"
        },
        "product_reference": "jasperreports-server-pro.src",
        "relates_to_product_reference": "rhev-m-3.4.z"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-3529",
      "discovery_date": "2014-09-04T00:00:00+00:00",
      "notes": [
        {
          "category": "other",
          "text": "Red Hat Product Security has determined that CVE-2014-3529 is not exploitable by default in JBoss Portal Platform as provided by Red Hat. This flaw would only be exploitable if the Apache POI library provided by JBoss Portal Platform were used by a custom application to process user-supplied XML documents.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "It was found that Apache POI would resolve entities in OOXML documents. A remote attacker able to supply OOXML documents that are parsed by Apache POI could use this flaw to read files accessible to the user running the application server, and potentially perform more advanced XML External Entity (XXE) attacks.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhev-m-3.4.z:jasperreports-server-pro.src",
          "rhev-m-3.5.z:jasperreports-server-pro.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-3529"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3529"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-3529"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhev-m-3.4.z:jasperreports-server-pro.src"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "rhev-m-3.5.z:jasperreports-server-pro.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
            "baseScore": 5.0
          },
          "products": [
            "rhev-m-3.4.z:jasperreports-server-pro.src",
            "rhev-m-3.5.z:jasperreports-server-pro.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhev-m-3.4.z:jasperreports-server-pro.src",
            "rhev-m-3.5.z:jasperreports-server-pro.src"
          ]
        }
      ],
      "title": "XML eXternal Entity (XXE) flaw"
    }
  ]
}