CVE-2015-0263

Severity
5.0MEDIUM
EPSS
2.6%
top 14.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 3
Latest updateOct 16

Description

XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Mavenorg.apache.camel:camel-core2.14.02.14.2+1
NVDapache/camel2.13.3+2

🔴Vulnerability Details

3
GHSA
Apache Camel XML External Entity vulnerability2018-10-16
OSV
Apache Camel XML External Entity vulnerability2018-10-16
CVEList
CVE-2015-0263: XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter2015-06-03

📋Vendor Advisories

2
Red Hat
Camel: XXE in via SAXSource expansion2015-03-17
Apache
Apache camel: CVE-2015-0263

💬Community

1
Bugzilla
CVE-2015-0263 Camel: XXE in via SAXSource expansion2015-03-18
CVE-2015-0263 (MEDIUM CVSS 5) | XML external entity (XXE) vulnerabi | cvebase.io