{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "entity expansion (billion laughs) flaw",
    "tracking": {
      "current_release_date": "2026-08-11T14:05:02+00:00",
      "generator": {
        "date": "2026-08-11T14:05:02+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2014-3574",
      "initial_release_date": "2014-08-18T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:05:02+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Virtualization 3.4.0",
            "product": {
              "name": "Red Hat Enterprise Virtualization 3.4.0",
              "product_id": "rhev-m-3.4.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhev_v2v:2"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Virtualization 3.5.0",
            "product": {
              "name": "Red Hat Enterprise Virtualization 3.5.0",
              "product_id": "rhev-m-3.5.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhev_v2v:2"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Satellite 560",
            "product": {
              "name": "Red Hat Satellite 560",
              "product_id": "rhn_satellite_5.6",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:network_proxy:5"
              }
            }
          },
          {
            "category": "product_version",
            "name": "apache-poi",
            "product": {
              "name": "apache-poi",
              "product_id": "apache-poi.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/apache-poi?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jasperreports-server-pro",
            "product": {
              "name": "jasperreports-server-pro",
              "product_id": "jasperreports-server-pro.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/jasperreports-server-pro?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "apache-poi.src as a component of Red Hat Satellite 560",
          "product_id": "rhn_satellite_5.6:apache-poi.src"
        },
        "product_reference": "apache-poi.src",
        "relates_to_product_reference": "rhn_satellite_5.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jasperreports-server-pro.src as a component of Red Hat Enterprise Virtualization 3.4.0",
          "product_id": "rhev-m-3.4.z:jasperreports-server-pro.src"
        },
        "product_reference": "jasperreports-server-pro.src",
        "relates_to_product_reference": "rhev-m-3.4.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jasperreports-server-pro.src as a component of Red Hat Enterprise Virtualization 3.5.0",
          "product_id": "rhev-m-3.5.z:jasperreports-server-pro.src"
        },
        "product_reference": "jasperreports-server-pro.src",
        "relates_to_product_reference": "rhev-m-3.5.z"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-3574",
      "discovery_date": "2014-09-04T00:00:00+00:00",
      "notes": [
        {
          "category": "other",
          "text": "Red Hat Product Security has determined that CVE-2014-3574 is not exploitable by default in JBoss Portal Platform as provided by Red Hat. This flaw would only be exploitable if the Apache POI library provided by JBoss Portal Platform were used by a custom application to process user-supplied XML documents.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "It was found that Apache POI would expand an unlimited number of entities in OOXML documents. A remote attacker able to supply OOXML documents that are parsed by Apache POI could use this flaw to trigger a denial of service attack via excessive CPU and memory consumption.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhev-m-3.4.z:jasperreports-server-pro.src",
          "rhev-m-3.5.z:jasperreports-server-pro.src",
          "rhn_satellite_5.6:apache-poi.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-3574"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3574"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-3574"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhev-m-3.4.z:jasperreports-server-pro.src",
            "rhn_satellite_5.6:apache-poi.src"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "rhev-m-3.5.z:jasperreports-server-pro.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
            "baseScore": 5.0
          },
          "products": [
            "rhev-m-3.4.z:jasperreports-server-pro.src",
            "rhev-m-3.5.z:jasperreports-server-pro.src",
            "rhn_satellite_5.6:apache-poi.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhev-m-3.4.z:jasperreports-server-pro.src",
            "rhev-m-3.5.z:jasperreports-server-pro.src",
            "rhn_satellite_5.6:apache-poi.src"
          ]
        }
      ],
      "title": "entity expansion (billion laughs) flaw"
    }
  ]
}