PT-2018-8384 · Red Hat · Jboss Eap

CVE-2017-7464

·

Published

2018-07-27

·

Updated

2023-02-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JBoss EAP version 7.0
Description The JAXP implementation used for SAX and DOM parsing in JBoss EAP is susceptible to certain XXE flaws. This could allow an attacker to cause a denial of service, server-side request forgery, or information disclosure if they can provide XML content for parsing.
Recommendations For JBoss EAP version 7.0, update the JAXP implementation to a version that is not vulnerable to XXE flaws.

Fix

DoS

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7464

Affected Products

Jboss Eap