Описание
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
A flaw was found when parsing XML files using XMLBeans 2.6.0 or below. The underlying parser created by XMLBeans could be susceptible to XML External Entity (XXE) attacks. The highest threat from this vulnerability is to confidentiality and system availability.
Меры по смягчению последствий
Affected users are advised to update to Apache XMLBeans 3.0.0 or above, which fixes this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | xmlbeans | Out of support scope | ||
| Red Hat CodeReady Studio 12 | xmlbeans | Affected | ||
| Red Hat Decision Manager 7 | xmlbeans | Not affected | ||
| Red Hat Integration Camel K 1 | xmlbeans | Not affected | ||
| Red Hat JBoss BRMS 6 | xmlbeans | Out of support scope | ||
| Red Hat JBoss Data Virtualization 6 | xmlbeans | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | xmlbeans | Not affected | ||
| Red Hat JBoss Fuse 6 | xmlbeans | Affected | ||
| Red Hat JBoss Fuse Service Works 6 | xmlbeans | Out of support scope | ||
| Red Hat JBoss SOA Platform 5 | xmlbeans | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
The XML parsers used by XMLBeans up to version 2.6.0 did not set the p ...
EPSS
7.4 High
CVSS3