It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
2018-07-26T15:29:00.307
2024-11-21T03:32:08.160
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | decision_manager | 7.0 | Yes |
Application | redhat | jboss_bpm_suite | 6.4 | Yes |
Application | redhat | jbpm | 6.5 | Yes |