Severity
5.0MEDIUM
EPSS
1.4%
top 19.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateMay 17

Description

Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gvc5-hqc3-j65q: Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Rem2022-05-17
CVEList
CVE-2013-6447: Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Rem2014-01-23

📋Vendor Advisories

1
Red Hat
Seam: XML eXternal Entity (XXE) flaw in remoting2014-01-20

💬Community

1
Bugzilla
CVE-2013-6447 JBoss Seam: XML eXternal Entity (XXE) flaw in remoting2013-12-19
CVE-2013-6447 (MEDIUM CVSS 5) | Multiple XML External Entity (XXE) | cvebase.io