CVE-2013-6447
published 2014-01-23CVE-2013-6447: Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.67%
84.1th percentile
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_seam_2_framework | <= 2.3.1 | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gvc5-hqc3-j65q: Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Rem
ghsa_unreviewed·2022-05-17
CVE-2013-6447 [MEDIUM] CWE-200 GHSA-gvc5-hqc3-j65q: Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Rem
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file.
Red Hat
Seam: XML eXternal Entity (XXE) flaw in remoting
vendor_redhat·2014-01-20·CVSS 5.0
CVE-2013-6447 [MEDIUM] CWE-611 Seam: XML eXternal Entity (XXE) flaw in remoting
Seam: XML eXternal Entity (XXE) flaw in remoting
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file.
Statement: This issue affects Seam 3 remoting, but Seam 3 is not shipped with any Red Hat products, and Seam 3 development has been terminated. This issue is not currently planned to be addressed in a future update to Seam 3.
Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 4 and 5; Red Hat JBoss Enterprise Portal Platform 5; Red Hat JBoss Enterprise SOA Platform 4 and 5; and Red Hat JBo
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-0045.htmlhttp://secunia.com/advisories/56572http://www.securitytracker.com/id/1029652https://bugzilla.redhat.com/show_bug.cgi?id=1044784https://github.com/seam2/jboss-seam/commit/090aa6252affc978a96c388e3fc2c1c2688d9bb5http://rhn.redhat.com/errata/RHSA-2014-0045.htmlhttp://secunia.com/advisories/56572http://www.securitytracker.com/id/1029652https://bugzilla.redhat.com/show_bug.cgi?id=1044784https://github.com/seam2/jboss-seam/commit/090aa6252affc978a96c388e3fc2c1c2688d9bb5
2014-01-23
Published