Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3682

Опубликовано: 17 фев. 2015
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer 6.0.x and 6.2.x allows remote attackers to read arbitrary files and possibly have other unspecified impact by importing a crafted BPMN2 file.

An XML External Entity (XXE) flaw was found in the jbpm-designer BPMN2 import function. A remote attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1jbpm-bpmn2Will not fix
Red Hat JBoss BRMS 5jbpm-bpmn2Fix deferred
Red Hat JBoss Data Virtualization 6jbpm-designerNot affected
Red Hat JBoss Fuse Service Works 6jbpm-designerNot affected
Red Hat JBoss SOA Platform 5jbpm-designerNot affected
Red Hat OpenShift Enterprise 2jbpm-bpmn2Will not fix
Red Hat JBoss BPMS 6.0jbpm-designerFixedRHSA-2015:023417.02.2015
Red Hat JBoss BRMS 6.0jbpm-designerFixedRHSA-2015:023517.02.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1148260jbpm-designer: XXE in BPMN2 import

EPSS

Процентиль: 84%
0.02109
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer 6.0.x and 6.2.x allows remote attackers to read arbitrary files and possibly have other unspecified impact by importing a crafted BPMN2 file.

github
больше 3 лет назад

XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer 6.0.x and 6.2.x allows remote attackers to read arbitrary files and possibly have other unspecified impact by importing a crafted BPMN2 file.

EPSS

Процентиль: 84%
0.02109
Низкий

5 Medium

CVSS2