Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8739

Опубликовано: 19 дек. 2016
Источник: redhat
CVSS3: 6.5
CVSS2: 5.8
EPSS Низкий

Описание

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.

Apache CXF JAX-RS implementation provides a number of Atom MessageBodyReaders. These readers use Apache Abdera Parser to parse Atom feeds or Entries, with this Parser expanding XML entities by default. It was found that this represents a major XXE risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6cxfNot affected
Red Hat JBoss BRMS 5cxfWill not fix
Red Hat JBoss BRMS 6cxfNot affected
Red Hat JBoss Data Grid 6cxfNot affected
Red Hat JBoss Data Virtualization 6cxfNot affected
Red Hat JBoss Enterprise Application Platform 5cxfUnder investigation
Red Hat JBoss Enterprise Application Platform 6cxfNot affected
Red Hat JBoss Enterprise Application Platform 7cxfNot affected
Red Hat JBoss Fuse 6cxfAffected
Red Hat JBoss Fuse Service Works 6.0.0cxfNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1406811apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE

EPSS

Процентиль: 85%
0.02672
Низкий

6.5 Medium

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.

CVSS3: 7.5
github
больше 3 лет назад

Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS

EPSS

Процентиль: 85%
0.02672
Низкий

6.5 Medium

CVSS3

5.8 Medium

CVSS2