Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-6440

Опубликовано: 11 дек. 2013
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

It was found that the ParserPool and Decrypter classes in the OpenSAML Java implementation resolved external entities, permitting XML External Entity (XXE) attacks. A remote attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Virtualization 6xmltoolingNot affected
Red Hat JBoss Enterprise Application Platform 5xmltoolingWill not fix
Red Hat JBoss Operations Network 3xmltoolingNot affected
Red Hat JBoss Portal 5xmltoolingWill not fix
Red Hat JBoss Portal 6xmltoolingAffected
Fuse ESB Enterprise 7.1.0FixedRHSA-2014:045230.04.2014
Fuse Management Console 7.1.0FixedRHSA-2014:045230.04.2014
Fuse MQ Enterprise 7.1.0FixedRHSA-2014:045230.04.2014
Red Hat JBoss BPMS 6.0xmltoolingFixedRHSA-2014:129123.09.2014
Red Hat JBoss BRMS 6.0xmltoolingFixedRHSA-2014:129023.09.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1043332Java: XML eXternal Entity (XXE) flaw in ParserPool and Decrypter

EPSS

Процентиль: 85%
0.02752
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

nvd
больше 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

debian
больше 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, ...

github
около 4 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in OpenSAML

EPSS

Процентиль: 85%
0.02752
Низкий

5 Medium

CVSS2