CVE-2017-7545
published 2018-07-26CVE-2017-7545: It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker…
PriorityP338medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
2.76%
84.6th percentile
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kie | jbpm-designer | — | — |
| redhat | decision_manager | — | — |
| redhat | jboss_bpm_suite | — | — |
| redhat | jbpm | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
XML External Entity Reference in jbpmmigration
ghsa·2022-05-13
CVE-2017-7545 [MEDIUM] CWE-611 XML External Entity Reference in jbpmmigration
XML External Entity Reference in jbpmmigration
It was discovered that the XmlUtils class in jbpmmigration performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
The related jbpm-designer project removed use of jbpmmigration completely as a result.
OSV
XML External Entity Reference in jbpmmigration
osv·2022-05-13
CVE-2017-7545 [MEDIUM] XML External Entity Reference in jbpmmigration
XML External Entity Reference in jbpmmigration
It was discovered that the XmlUtils class in jbpmmigration performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
The related jbpm-designer project removed use of jbpmmigration completely as a result.
Red Hat
jbpmmigration: XXE vulnerability in XmlUtils
vendor_redhat·2017-11-30·CVSS 6.5
CVE-2017-7545 [MEDIUM] CWE-611 jbpmmigration: XXE vulnerability in XmlUtils
jbpmmigration: XXE vulnerability in XmlUtils
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
It was discovered that the XmlUtils class in jbpmmigration performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
Package: jbpmmigration (Red Hat JBoss BRMS 5) - Will not fix
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102179https://access.redhat.com/errata/RHSA-2017:3354https://access.redhat.com/errata/RHSA-2017:3355https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7545https://github.com/kiegroup/jbpm-designer/commit/a143f3b92a6a5a527d929d68c02a0c5d914ab81dhttp://www.securityfocus.com/bid/102179https://access.redhat.com/errata/RHSA-2017:3354https://access.redhat.com/errata/RHSA-2017:3355https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7545https://github.com/kiegroup/jbpm-designer/commit/a143f3b92a6a5a527d929d68c02a0c5d914ab81d
2018-07-26
Published