PT-2015-3732 · Red Hat · Jbpm-Designer

Published

2015-02-20

·

Updated

2015-03-24

·

CVE-2014-3682

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions jbpm-designer versions 6.0.x through 6.2.x
Description The issue allows remote attackers to read arbitrary files and possibly have other unspecified impact by importing a crafted BPMN2 file, due to an XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function.
Recommendations For versions 6.0.x through 6.2.x, consider disabling the JBPMBpmn2ResourceImpl function until a patch is available to prevent the import of crafted BPMN2 files. Restrict access to the bpmn2/resource/JBPMBpmn2ResourceImpl.java module to minimize the risk of exploitation. Avoid using the function to import untrusted BPMN2 files until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-3682

Affected Products

Jbpm-Designer