CVE-2014-3481
published 2014-07-07CVE-2014-3481: org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which…
PriorityP432medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.03%
86.0th percentile
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | <= 6.2.3 | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JAX-RS: Information disclosure via XML eXternal Entity (XXE)
vendor_redhat·2014-06-05·CVSS 5.0
CVE-2014-3481 [MEDIUM] CWE-611 JAX-RS: Information disclosure via XML eXternal Entity (XXE)
JAX-RS: Information disclosure via XML eXternal Entity (XXE)
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
It was found that the default context parameters as provided to RESTEasy deployments by JBoss EAP did not explicitly disable external entity expansion for RESTEasy. A remote attacker could use this flaw to perform XML External Entity (XXE) attacks on RESTEasy applications accepting XML input.
Package: jboss-as-jaxrs (Red Hat JBoss Data Grid 6) - Affected
GHSA
GHSA-xm6x-8fqh-w3x3: org
ghsa_unreviewed·2022-05-17
CVE-2014-3481 [MEDIUM] CWE-200 GHSA-xm6x-8fqh-w3x3: org
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3481 wildfly: JBoss AS JAX-RS: Information disclosure via XML eXternal Entity (XXE) [fedora-all]
bugzilla·2014-07-30·CVSS 5.0
CVE-2014-3481 [MEDIUM] CVE-2014-3481 wildfly: JBoss AS JAX-RS: Information disclosure via XML eXternal Entity (XXE) [fedora-all]
CVE-2014-3481 wildfly: JBoss AS JAX-RS: Information disclosure via XML eXternal Entity (XXE) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2014-3481 JBoss AS JAX-RS: Information disclosure via XML eXternal Entity (XXE)
bugzilla·2014-06-05·CVSS 5.0
CVE-2014-3481 [MEDIUM] CVE-2014-3481 JBoss AS JAX-RS: Information disclosure via XML eXternal Entity (XXE)
CVE-2014-3481 JBoss AS JAX-RS: Information disclosure via XML eXternal Entity (XXE)
IssueDescription:
It was found that the default context parameters as provided to RESTEasy deployments by JBoss EAP did not explicitly disable external entity expansion for RESTEasy. A remote attacker could use this flaw to perform XML External Entity (XXE) attacks on RESTEasy applications accepting XML input.
Discussion:
Acknowledgements:
This issue was discovered by the Red Hat JBoss Enterprise Application Platform QE team.
---
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.2.4
Via RHSA-2014:0797 https://rhn.redhat.com/errata/RHSA-2014-0797.html
---
This issue has been addressed in following products:
JBEAP 6.2 for RHEL 5
Via RHSA-2014:079
http://rhn.redhat.com/errata/RHSA-2014-0797.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0798.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0799.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0765.htmlhttp://www.securitytracker.com/id/1032017https://bugzilla.redhat.com/show_bug.cgi?id=1105242https://exchange.xforce.ibmcloud.com/vulnerabilities/94939http://rhn.redhat.com/errata/RHSA-2014-0797.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0798.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0799.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0765.htmlhttp://www.securitytracker.com/id/1032017https://bugzilla.redhat.com/show_bug.cgi?id=1105242https://exchange.xforce.ibmcloud.com/vulnerabilities/94939
2014-07-07
Published