CVE-2014-9360: Scalix Web Access
Medium severity, CVSS 6.4. EPSS: 1.4% chance of exploitation in the next 30 days.
XML external entity (XXE) vulnerability in Scalix Web Access 11.4.6.12377 and 12.2.0.14697 allows remote attackers to read arbitrary files and trigger requests to intranet servers via a crafted request.
Affected products
- Scalix Web Access: version 11.4.6.12377 only; version 12.2.0.14697 only
Published 2014-12-10. Last modified 2026-06-17.