CVE-2011-5245
published 2012-11-23CVE-2011-5245: The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity…
PriorityP433medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.21%
86.8th percentile
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | resteasy | <= 2.3.1 | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
RESTEasy: XML eXternal Entity (XXE) flaw
vendor_redhat·2011-12-30·CVSS 5.0
CVE-2011-5245 [MEDIUM] CWE-611 RESTEasy: XML eXternal Entity (XXE) flaw
RESTEasy: XML eXternal Entity (XXE) flaw
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
Package: Security (Red Hat JBoss BRMS 5) - Affected
Package: Teiid (Red Hat JBoss Data Virtualization 6) - Affected
Package: Security (Red Hat JBoss SOA Platform 5) - Affected
Package: resteasy (Red Hat Storage 2.1) - Affected
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
ghsa·2022-05-17·CVSS 5.0
CVE-2011-5245 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
osv·2022-05-17·CVSS 5.0
CVE-2011-5245 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-0441.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0519.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1056.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1057.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1058.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1059.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1125.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0371.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0372.htmlhttp://secunia.com/advisories/47832http://secunia.com/advisories/50084http://secunia.com/advisories/57716http://secunia.com/advisories/57719http://www.osvdb.org/78680http://www.securityfocus.com/bid/51766https://bugzilla.redhat.com/show_bug.cgi?id=785631https://exchange.xforce.ibmcloud.com/vulnerabilities/72808https://issues.jboss.org/browse/RESTEASY-647https://issues.jboss.org/browse/RESTEASY/fixforversion/12318708http://rhn.redhat.com/errata/RHSA-2012-0441.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0519.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1056.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1057.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1058.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1059.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1125.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0371.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0372.htmlhttp://secunia.com/advisories/47832http://secunia.com/advisories/50084http://secunia.com/advisories/57716http://secunia.com/advisories/57719http://www.osvdb.org/78680http://www.securityfocus.com/bid/51766https://bugzilla.redhat.com/show_bug.cgi?id=785631https://exchange.xforce.ibmcloud.com/vulnerabilities/72808https://issues.jboss.org/browse/RESTEASY-647https://issues.jboss.org/browse/RESTEASY/fixforversion/12318708
2012-11-23
Published