VulnerabilityModified
CVE-2017-7545
A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
MEDIUM 6.5EPSS 2.76%
Does this matter?
Lower severity and a low EPSS score (2.76%). Track it; it rarely justifies an emergency change on its own.
Description
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.76% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- redhat/decision manager · redhat/jboss bpm suite · redhat/jbpm
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/102179Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3354Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3355Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7545Issue Tracking, Patch, Vendor Advisory
- https://github.com/kiegroup/jbpm-designer/commit/a143f3b92a6a5a527d929d68c02a0c5d914ab81dPatch, Third Party Advisory
- http://www.securityfocus.com/bid/102179Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3354Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3355Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7545Issue Tracking, Patch, Vendor Advisory
- https://github.com/kiegroup/jbpm-designer/commit/a143f3b92a6a5a527d929d68c02a0c5d914ab81dPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.