CVE-2014-3682
20.02.2015, 16:59
XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer 6.0.x and 6.2.x allows remote attackers to read arbitrary files and possibly have other unspecified impact by importing a crafted BPMN2 file.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jbpm-designer | 6.0.0 |
redhat | jbpm-designer | 6.0.1 |
redhat | jbpm-designer | 6.2.0 |
𝑥
= Vulnerable software versions
References