PT-2015-3732 · Red Hat · Jbpm-Designer
Published
2015-02-20
·
Updated
2015-03-24
·
CVE-2014-3682
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
jbpm-designer versions 6.0.x through 6.2.x
Description
The issue allows remote attackers to read arbitrary files and possibly have other unspecified impact by importing a crafted BPMN2 file, due to an XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function.
Recommendations
For versions 6.0.x through 6.2.x, consider disabling the JBPMBpmn2ResourceImpl function until a patch is available to prevent the import of crafted BPMN2 files. Restrict access to the bpmn2/resource/JBPMBpmn2ResourceImpl.java module to minimize the risk of exploitation. Avoid using the function to import untrusted BPMN2 files until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jbpm-Designer