It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1451960 | Issue Tracking Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/98546 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-05-18 08:29
Updated : 2017-05-31 11:13
NVD link : CVE-2017-7503
Mitre link : CVE-2017-7503
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
redhat
- jboss_enterprise_application_platform