Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8125

Опубликовано: 22 дек. 2014
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.

It was discovered that the jBPM runtime performed expansion of external parameter entities while executing BPMN2 files. A remote attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XML eXternal Entity (XXE) attacks.

Отчет

Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; and Red Hat JBoss Enterprise SOA Platform 4 and 5 are now in Phase 3, Extended Life Support, of their respective life cycles. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat JBoss Middleware and Red Hat JBoss Operations Network Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5jbpmWill not fix
Red Hat JBoss Data Virtualization 6jbpmAffected
Red Hat JBoss Enterprise Application Platform 5jbpmWill not fix
Red Hat JBoss Enterprise Web Server 1fuse-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7Will not fix
Red Hat JBoss Fuse Service Works 6jbpmAffected
Red Hat JBoss SOA Platform 4jbpmWill not fix
Red Hat JBoss SOA Platform 5jbpmWill not fix
Red Hat JBoss BPMS 6.0jbpmFixedRHSA-2015:085116.04.2015
Red Hat JBoss BRMS 6.0jbpmFixedRHSA-2015:085016.04.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1169553jBPM: BPMN2 file processing XXE in Process Execution

EPSS

Процентиль: 76%
0.00957
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.

github
больше 3 лет назад

Improper Input Validation in Drools and jBPM

EPSS

Процентиль: 76%
0.00957
Низкий

5 Medium

CVSS2