Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3674

Опубликовано: 15 мар. 2016
Источник: redhat
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

It was found that several XML parsers used by XStream had default settings that would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6xstreamAffected
Red Hat Enterprise Linux 7xstreamAffected
Red Hat Enterprise Virtualization 3jasperreports-server-proAffected
Red Hat JBoss A-MQ 6xstreamAffected
Red Hat JBoss BRMS 5xstreamWill not fix
Red Hat JBoss BRMS 6xstreamAffected
Red Hat JBoss Data Grid 6xstreamAffected
Red Hat JBoss Fuse Service Works 6xstreamAffected
Red Hat JBoss Portal 6xstreamAffected
Red Hat JBoss SOA Platform 5xstreamWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1321789XStream: enabled processing of external entities

EPSS

Процентиль: 94%
0.08179
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 10 лет назад

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

CVSS3: 7.5
nvd
больше 10 лет назад

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

CVSS3: 7.5
debian
больше 10 лет назад

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDri ...

CVSS3: 7.5
github
около 6 лет назад

XML External Entity Injection in XStream

EPSS

Процентиль: 94%
0.08179
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2