Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7464

Опубликовано: 11 мая 2017
Источник: redhat
CVSS3: 8.7
CVSS2: 4

Описание

It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.

It was found that the JAXP implementation used in EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.

Меры по смягчению последствий

Enable the security features of the DocumentBuilderFactory or SaxParserFactory as described by OWASP: https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Prevention_Cheat_Sheet#JAXP_DocumentBuilderFactory.2C_SAXParserFactory_and_DOM4J

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 7XML FrameworksWill not fix
Red Hat JBoss Enterprise Web Server 3tomcatNot affected
Red Hat Mobile Application Platform 4securityNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1439520JBoss: JAXP in EAP 7.0 allows info disclosure via XXE

8.7 High

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.7
nvd
больше 7 лет назад

It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.

CVSS3: 9.8
github
больше 3 лет назад

It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.

8.7 High

CVSS3

4 Medium

CVSS2