Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3674

Опубликовано: 15 мар. 2016
Источник: redhat
CVSS3: 5.3
CVSS2: 5

Описание

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

It was found that several XML parsers used by XStream had default settings that would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6xstreamAffected
Red Hat Enterprise Linux 7xstreamAffected
Red Hat Enterprise Virtualization 3jasperreports-server-proAffected
Red Hat JBoss A-MQ 6.2.1xstreamAffected
Red Hat JBoss BRMS 5xstreamWill not fix
Red Hat JBoss BRMS 6xstreamAffected
Red Hat JBoss Data Grid 6xstreamAffected
Red Hat JBoss Fuse Service Works 6xstreamAffected
Red Hat JBoss Portal 6xstreamAffected
Red Hat JBoss SOA Platform 5xstreamWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1321789XStream: enabled processing of external entities

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

CVSS3: 7.5
nvd
больше 9 лет назад

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

CVSS3: 7.5
debian
больше 9 лет назад

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDri ...

CVSS3: 7.5
github
больше 5 лет назад

XML External Entity Injection in XStream

5.3 Medium

CVSS3

5 Medium

CVSS2