Описание
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
It was found that several XML parsers used by XStream had default settings that would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | xstream | Affected | ||
| Red Hat Enterprise Linux 7 | xstream | Affected | ||
| Red Hat Enterprise Virtualization 3 | jasperreports-server-pro | Affected | ||
| Red Hat JBoss A-MQ 6.2.1 | xstream | Affected | ||
| Red Hat JBoss BRMS 5 | xstream | Will not fix | ||
| Red Hat JBoss BRMS 6 | xstream | Affected | ||
| Red Hat JBoss Data Grid 6 | xstream | Affected | ||
| Red Hat JBoss Fuse Service Works 6 | xstream | Affected | ||
| Red Hat JBoss Portal 6 | xstream | Affected | ||
| Red Hat JBoss SOA Platform 5 | xstream | Will not fix |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
5 Medium
CVSS2
Связанные уязвимости
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDri ...
5.3 Medium
CVSS3
5 Medium
CVSS2