CVE-2013-6447
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote…
Does this matter?
Lower severity and a low EPSS score (2.67%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.67% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/jboss seam 2 framework
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2014-0045.html
- http://secunia.com/advisories/56572Vendor Advisory
- http://www.securitytracker.com/id/1029652
- https://bugzilla.redhat.com/show_bug.cgi?id=1044784Patch, Vendor Advisory
- https://github.com/seam2/jboss-seam/commit/090aa6252affc978a96c388e3fc2c1c2688d9bb5
- http://rhn.redhat.com/errata/RHSA-2014-0045.html
- http://secunia.com/advisories/56572Vendor Advisory
- http://www.securitytracker.com/id/1029652
- https://bugzilla.redhat.com/show_bug.cgi?id=1044784Patch, Vendor Advisory
- https://github.com/seam2/jboss-seam/commit/090aa6252affc978a96c388e3fc2c1c2688d9bb5
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.