MEDIUM · 6.5

CVE-2017-7545

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessibl...

Vulnerability Description

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
RedhatDecision Manager7.0
RedhatJboss Bpm Suite6.4
RedhatJbpm6.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-7545?

CVE-2017-7545 is a vulnerability with a CVSS score of 6.5 (MEDIUM). It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessibl...

How severe is CVE-2017-7545?

CVE-2017-7545 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-7545?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Decision Manager, Redhat Jboss Bpm Suite, Redhat Jbpm.