PT-2018-8384 · Red Hat · Jboss Eap

CVE-2017-7464

·

Publicado

2018-07-27

·

Atualizado

2023-02-12

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JBoss EAP version 7.0
Description The JAXP implementation used for SAX and DOM parsing in JBoss EAP is susceptible to certain XXE flaws. This could allow an attacker to cause a denial of service, server-side request forgery, or information disclosure if they can provide XML content for parsing.
Recommendations For JBoss EAP version 7.0, update the JAXP implementation to a version that is not vulnerable to XXE flaws.

Correção

DoS

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7464

Produtos afetados

Jboss Eap