CVE-2014-8125
published 2015-04-21CVE-2014-8125: XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified…
PriorityP344high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.66%
84.0th percentile
XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | drools | <= 6.1.0 | — |
| redhat | jbpm | <= 6.1.0 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in Drools and jBPM
osv·2022-05-17
CVE-2014-8125 [HIGH] Improper Input Validation in Drools and jBPM
Improper Input Validation in Drools and jBPM
XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
GHSA
Improper Input Validation in Drools and jBPM
ghsa·2022-05-17
CVE-2014-8125 [HIGH] CWE-20 Improper Input Validation in Drools and jBPM
Improper Input Validation in Drools and jBPM
XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
Red Hat
jBPM: BPMN2 file processing XXE in Process Execution
vendor_redhat·2014-12-22·CVSS 7.5
CVE-2014-8125 [HIGH] CWE-611 jBPM: BPMN2 file processing XXE in Process Execution
jBPM: BPMN2 file processing XXE in Process Execution
XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
It was discovered that the jBPM runtime performed expansion of external parameter entities while executing BPMN2 files. A remote attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XML eXternal Entity (XXE) attacks.
Statement: Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; and Red Hat JBoss Enterprise SOA Platform 4 and 5 are now in Phase 3, Extended Life Support, of their respective life cycles. This issue has been rated as having Modera
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1169553https://github.com/droolsjbpm/drools/commit/c48464c3b246e6ef0d4cd0dbf67e83ccd532c6d3https://github.com/droolsjbpm/jbpm/commit/713e8073ecf45623cfc5c918c5cbf700203f46e5http://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1169553https://github.com/droolsjbpm/drools/commit/c48464c3b246e6ef0d4cd0dbf67e83ccd532c6d3https://github.com/droolsjbpm/jbpm/commit/713e8073ecf45623cfc5c918c5cbf700203f46e5
2015-04-21
Published