CVE-2017-7503
published 2017-05-18CVE-2017-7503: It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to…
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.01%
78.6th percentile
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2f38-5w6m-7c6f: It was found that the Red Hat JBoss EAP 7
ghsa_unreviewed·2022-05-17
CVE-2017-7503 [CRITICAL] CWE-611 GHSA-2f38-5w6m-7c6f: It was found that the Red Hat JBoss EAP 7
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
Red Hat
EAP: XXE issue in TransformerFactory
vendor_redhat·2017-05-18·CVSS 9.8
CVE-2017-7503 [CRITICAL] EAP: XXE issue in TransformerFactory
EAP: XXE issue in TransformerFactory
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
Mitigation: This issue affects processing of XML content from an untrusted source using a javax.xml.transform.TransformerFactory. The only safe way to process untrusted XML content with a TransformerFactory is to use the StAX API. StAX is a safe implementation on EAP 7.0.x beca
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7503 wildfly: EAP: XXE issue in TransformerFactory [fedora-all]
bugzilla·2017-05-18·CVSS 9.8
CVE-2017-7503 [CRITICAL] CVE-2017-7503 wildfly: EAP: XXE issue in TransformerFactory [fedora-all]
CVE-2017-7503 wildfly: EAP: XXE issue in TransformerFactory [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2017-7503 EAP: XXE issue in TransformerFactory
bugzilla·2017-05-18·CVSS 9.8
CVE-2017-7503 [CRITICAL] CVE-2017-7503 EAP: XXE issue in TransformerFactory
CVE-2017-7503 EAP: XXE issue in TransformerFactory
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
Discussion:
Created wildfly tracking bugs for this issue:
Affects: fedora-all [bug 1451961]
---
Acknowledgments:
Name: Jason Shepherd (Red Hat Product Security), Katerina Novotna (Red Hat Quality Engineering)
---
It will be difficult to fix this issue in Xerces. The patch which contains the fix in OpenJDK contains many other related changes. It appears to be fixed in revision 292:7b89fed7212b of the jaxp repo, http://hg.openjdk.java.net/jdk8/jdk8/jaxp/
An alternative might be to remove Xerces
2017-05-18
Published