CVE-2013-6447
23.01.2014, 00:55
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jboss_seam_2_framework | 𝑥 ≤ 2.3.1 |
redhat | jboss_seam_2_framework | 2.0.0:beta1 |
redhat | jboss_seam_2_framework | 2.0.0:cr1 |
redhat | jboss_seam_2_framework | 2.0.0:cr2 |
redhat | jboss_seam_2_framework | 2.0.0:cr3 |
redhat | jboss_seam_2_framework | 2.0.0:ga |
redhat | jboss_seam_2_framework | 2.0.1:cr1 |
redhat | jboss_seam_2_framework | 2.0.1:cr2 |
redhat | jboss_seam_2_framework | 2.0.1:ga |
redhat | jboss_seam_2_framework | 2.0.2:cr1 |
redhat | jboss_seam_2_framework | 2.0.2:cr2 |
redhat | jboss_seam_2_framework | 2.0.2:ga |
redhat | jboss_seam_2_framework | 2.0.2:sp1 |
redhat | jboss_seam_2_framework | 2.0.3:cr1 |
redhat | jboss_seam_2_framework | 2.1.0:alpha1 |
redhat | jboss_seam_2_framework | 2.1.0:beta1 |
redhat | jboss_seam_2_framework | 2.1.0:cr1 |
redhat | jboss_seam_2_framework | 2.1.0:ga |
redhat | jboss_seam_2_framework | 2.1.0:sp1 |
redhat | jboss_seam_2_framework | 2.1.1:cr1 |
redhat | jboss_seam_2_framework | 2.1.1:cr2 |
redhat | jboss_seam_2_framework | 2.1.1:ga |
redhat | jboss_seam_2_framework | 2.1.2 |
redhat | jboss_seam_2_framework | 2.1.2:cr1 |
redhat | jboss_seam_2_framework | 2.1.2:cr2 |
redhat | jboss_seam_2_framework | 2.2.0:cr1 |
redhat | jboss_seam_2_framework | 2.2.0:ga |
redhat | jboss_seam_2_framework | 2.2.1 |
redhat | jboss_seam_2_framework | 2.2.1:cr1 |
redhat | jboss_seam_2_framework | 2.2.1:cr2 |
redhat | jboss_seam_2_framework | 2.2.1:cr3 |
redhat | jboss_seam_2_framework | 2.2.2 |
redhat | jboss_seam_2_framework | 2.3.0 |
redhat | jboss_seam_2_framework | 2.3.0:alpha |
redhat | jboss_seam_2_framework | 2.3.0:beta1 |
redhat | jboss_seam_2_framework | 2.3.0:beta2 |
redhat | jboss_seam_2_framework | 2.3.0:cr1 |
redhat | jboss_seam_2_framework | 2.3.1:cr1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References