CVE-2017-7545

MEDIUM

jbpmmigration 6.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102179
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3355
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3354
Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7545

Scores

CVSS v3 6.5
EPSS 0.0276
EPSS Percentile 84.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (4)
org.jbpm.jbpm5/jbpmmigration 0Maven
redhat/decision_manager 7.0
redhat/jboss_bpm_suite 6.4
redhat/jbpm 6.5
Published Jul 26, 2018
Tracked Since Feb 18, 2026