Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-6440

Опубликовано: 11 дек. 2013
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

It was found that the ParserPool and Decrypter classes in the OpenSAML Java implementation resolved external entities, permitting XML External Entity (XXE) attacks. A remote attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Virtualization 6xmltoolingNot affected
Red Hat JBoss Enterprise Application Platform 5xmltoolingWill not fix
Red Hat JBoss Enterprise Web Server 1fuse-6.0Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-othersWill not fix
Red Hat JBoss Operations Network 3xmltoolingNot affected
Red Hat JBoss Portal 5xmltoolingWill not fix
Red Hat JBoss Portal 6xmltoolingAffected
Fuse ESB Enterprise 7.1.0FixedRHSA-2014:045230.04.2014
Fuse Management Console 7.1.0FixedRHSA-2014:045230.04.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1043332Java: XML eXternal Entity (XXE) flaw in ParserPool and Decrypter

EPSS

Процентиль: 73%
0.0075
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

nvd
почти 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

debian
почти 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, ...

github
больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in OpenSAML

EPSS

Процентиль: 73%
0.0075
Низкий

5 Medium

CVSS2