CVE-2017-7545
26.07.2018, 15:29
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | decision_manager | 7.0 |
redhat | jboss_bpm_suite | 6.4 |
redhat | jbpm | 6.5 |
𝑥
= Vulnerable software versions
References