CVE-2015-0263
published 2015-06-03CVE-2015-0263: XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2…
PriorityP338medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
7.53%
93.8th percentile
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | <= 2.13.3 | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Camel: XXE in via SAXSource expansion
vendor_redhat·2015-03-17·CVSS 5.0
CVE-2015-0263 [MEDIUM] CWE-611 Camel: XXE in via SAXSource expansion
Camel: XXE in via SAXSource expansion
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
It was found that Apache Camel's XML converter performed XML External Entity (XXE) expansion. A remote attacker able to submit an SAXSource containing an XXE declaration could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Package: camel (OpenShift Enterprise 1) - Will not fix
Package: camel (Red Hat OpenShift Enterprise 2) - Affected
Apache
Apache camel: CVE-2015-0263
vendor_apache·CVSS 5.0
CVE-2015-0263 [MEDIUM] Apache camel: CVE-2015-0263
Apache camel: CVE-2015-0263
2.13.0 up to 2.13.3, 2.14.0 up to 2.14.1 2.13.4, 2.14.2, 2.15.0 and newer MEDIUM The XML converter setup in Apache Camel allows remote attackers to read arbitrary files via an SAXSource containing an XML External Entity (XXE) declaration. 2014
Severity: medium
GHSA
Apache Camel XML External Entity vulnerability
ghsa·2018-10-16
CVE-2015-0263 [MEDIUM] CWE-611 Apache Camel XML External Entity vulnerability
Apache Camel XML External Entity vulnerability
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
OSV
Apache Camel XML External Entity vulnerability
osv·2018-10-16
CVE-2015-0263 [MEDIUM] Apache Camel XML External Entity vulnerability
Apache Camel XML External Entity vulnerability
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
No detection rules found.
No public exploits indexed.
arXiv
A Match Made in Heaven? AI-driven Matching of Vulnerabilities and Security Unit Tests
arxiv_fulltext·2026-01-22
A Match Made in Heaven? AI-driven Matching of Vulnerabilities and Security Unit Tests
A Match Made in Heaven? AI-driven Matching of Vulnerabilities and Security Unit Tests
Emanuele Iannone
0000-0001-7489-9969
Hamburg University of Technology
Hamburg
Germany
[email protected]
Quang-Cuong Bui
0000-0001-6072-9213
Hamburg University of Technology
Hamburg
Germany
[email protected]
Riccardo Scandariato
0000-0003-3591-7671
Hamburg University of Technology
Hamburg
Germany
[email protected]
showcomments
showcommentsfalse
peerreview
peerreviewfalse
gray75gray.25
gray50gray.5
gray40gray.6
gray30gray.7
gray25gray.75
gray20gray.8
gray15gray.85
gray10gray.9
gray05gray.95
redbgHTMLF2968F
greenbgHTMLCDE4AE
ghdiffredbgHTMLffccce
ghdiffgreenbgHTMLabefbc
goalcolorHTMLfffff2
rqboxcolorHTMLf2f2ff
rqanswercolorHTMLfaf9f5
takeawaycolorHTMLf2fff2
darkgreenHTML009B55
[1]
Bugzilla
CVE-2015-0263 Camel: XXE in via SAXSource expansion
bugzilla·2015-03-18·CVSS 5.0
CVE-2015-0263 [MEDIUM] CVE-2015-0263 Camel: XXE in via SAXSource expansion
CVE-2015-0263 Camel: XXE in via SAXSource expansion
It was found that Apache Camel's XML converter performed XML External Entity (XXE) expansion. A remote attacker able to submit an SAXSource containing a XXE declaration could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Upstream patch:
https://git-wip-us.apache.org/repos/asf?p=camel.git;a=commitdiff;h=7d19340bcdb42f7aae584d9c5003ac4f7ddaee36
External References:
https://camel.apache.org/security-advisories.data/CVE-2015-0263.txt.asc
Discussion:
This issue has been addressed in the following products:
JBoss Fuse/A-MQ 6.1.0
Via RHSA-2015:1041 https://rhn.redhat.com/errata/RHSA-2015-1041.html
---
This issue has been addressed in the foll
http://rhn.redhat.com/errata/RHSA-2015-1041.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1538.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1539.htmlhttp://www.securitytracker.com/id/1032442https://camel.apache.org/security-advisories.data/CVE-2015-0263.txt.aschttps://git-wip-us.apache.org/repos/asf?p=camel.git%3Ba=commitdiff%3Bh=7d19340bcdb42f7aae584d9c5003ac4f7ddaee36https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://rhn.redhat.com/errata/RHSA-2015-1041.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1538.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1539.htmlhttp://www.securitytracker.com/id/1032442https://camel.apache.org/security-advisories.data/CVE-2015-0263.txt.aschttps://git-wip-us.apache.org/repos/asf?p=camel.git%3Ba=commitdiff%3Bh=7d19340bcdb42f7aae584d9c5003ac4f7ddaee36https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2015-06-03
Published