Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0264

Опубликовано: 17 мар. 2015
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.

It was found that Apache Camel performed XML External Entity (XXE) expansion when evaluating invalid XML Strings or invalid XML GenericFile objects. A remote attacker able to submit a crafted XML message could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1camelWill not fix
Red Hat JBoss Enterprise Web Server 1amq-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7Will not fix
Red Hat JBoss Enterprise Web Server 1fuse-mq-7Will not fix
Red Hat OpenShift Enterprise 2camelAffected
Red Hat JBoss A-MQ 6.1FixedRHSA-2015:104101.06.2015
Red Hat JBoss BPMS 6.0CamelFixedRHSA-2015:153903.08.2015
Red Hat JBoss BRMS 6.0CamelFixedRHSA-2015:153803.08.2015
Red Hat JBoss Fuse 6.1FixedRHSA-2015:104101.06.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1203341Camel: XXE via XPath expression evaluation

EPSS

Процентиль: 83%
0.02016
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.

github
больше 7 лет назад

Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile object

EPSS

Процентиль: 83%
0.02016
Низкий

5 Medium

CVSS2