Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2175

Опубликовано: 27 мая 2016
Источник: redhat
CVSS3: 5.4
CVSS2: 5.8
EPSS Низкий

Описание

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

It was found that the parsing of XMP and other XML formats in PDF by Apache PDFBox would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6pdfboxAffected
Red Hat JBoss BRMS 6pdfboxAffected
Red Hat JBoss Fuse 6pdfboxAffected
Red Hat JBoss Fuse Service Works 6pdfboxNot affected
Red Hat JBoss Portal 6pdfboxWill not fix
Red Hat Satellite 5pdfboxAffected
Red Hat JBoss A-MQ 6.3FixedRHSA-2017:017919.01.2017
Red Hat JBoss BPMS 6.4FixedRHSA-2017:024902.02.2017
Red Hat JBoss BRMS 6.4FixedRHSA-2017:024802.02.2017
Red Hat JBoss Data Virtualization 6.3pdfboxFixedRHSA-2017:027214.02.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1340396pdfbox: XML External Entity vulnerability

EPSS

Процентиль: 91%
0.04797
Низкий

5.4 Medium

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 10 лет назад

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

CVSS3: 7.8
nvd
около 10 лет назад

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

CVSS3: 7.8
debian
около 10 лет назад

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly ini ...

CVSS3: 7.8
github
почти 8 лет назад

High severity vulnerability that affects org.apache.pdfbox:pdfbox

EPSS

Процентиль: 91%
0.04797
Низкий

5.4 Medium

CVSS3

5.8 Medium

CVSS2