CVE-2017-7464
published 2018-07-27CVE-2017-7464: It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to…
PriorityP342critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.91%
77.5th percentile
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9x6m-hc4p-vjq7: It was found that the JAXP implementation used in JBoss EAP 7
ghsa_unreviewed·2022-05-13
CVE-2017-7464 [CRITICAL] CWE-611 GHSA-9x6m-hc4p-vjq7: It was found that the JAXP implementation used in JBoss EAP 7
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.
Red Hat
JBoss: JAXP in EAP 7.0 allows info disclosure via XXE
vendor_redhat·2017-05-11·CVSS 8.7
CVE-2017-7464 [HIGH] CWE-611 JBoss: JAXP in EAP 7.0 allows info disclosure via XXE
JBoss: JAXP in EAP 7.0 allows info disclosure via XXE
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.
It was found that the JAXP implementation used in EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.
Mitigation: Enable the security features of the DocumentBuilderFactory or SaxParserFactory as described by OWASP:
https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Prevention_Cheat_Sheet#JAXP_DocumentBuilderFactory.2C_SAXParserFact
No detection rules found.
No public exploits indexed.
2018-07-27
Published