Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7545

Опубликовано: 30 нояб. 2017
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.

It was discovered that the XmlUtils class in jbpmmigration performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5jbpmmigrationWill not fix
Red Hat JBoss BPMS 6.4jbpmmigrationFixedRHSA-2017:335530.11.2017
Red Hat JBoss BRMS 6.4jbpmmigrationFixedRHSA-2017:335430.11.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1474822jbpmmigration: XXE vulnerability in XmlUtils

EPSS

Процентиль: 74%
0.00815
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 7 лет назад

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.

CVSS3: 6.5
github
больше 3 лет назад

XML External Entity Reference in jbpmmigration

EPSS

Процентиль: 74%
0.00815
Низкий

6.5 Medium

CVSS3