Описание
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
It was found that the default context parameters as provided to RESTEasy deployments by JBoss EAP did not explicitly disable external entity expansion for RESTEasy. A remote attacker could use this flaw to perform XML External Entity (XXE) attacks on RESTEasy applications accepting XML input.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Data Grid 6 | jboss-as-jaxrs | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | others | Not affected | ||
| Red Hat JBoss Data Grid 6.3 | Fixed | RHSA-2014:0895 | 16.07.2014 | |
| Red Hat JBoss Data Virtualization 6.0 | jboss-as-jaxrs | Fixed | RHSA-2015:0765 | 31.03.2015 |
| Red Hat JBoss Data Virtualization 6.1 | Fixed | RHSA-2015:0675 | 11.03.2015 | |
| Red Hat JBoss Enterprise Application Platform 6.2 | jboss-as-jaxrs | Fixed | RHSA-2014:0797 | 26.06.2014 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 | apache-cxf | Fixed | RHSA-2014:0798 | 26.06.2014 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 | hibernate4-eap6 | Fixed | RHSA-2014:0798 | 26.06.2014 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 | jboss-aesh | Fixed | RHSA-2014:0798 | 26.06.2014 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 | jboss-as-appclient | Fixed | RHSA-2014:0798 | 26.06.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBo ...
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
EPSS
5 Medium
CVSS2