PT-2015-5457 · Red Hat · Red Hat Jboss Bpm Suite

David Jorm

·

Published

2015-08-11

·

Updated

2018-01-05

·

CVE-2015-1818

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat JBoss BPM Suite versions prior to 6.1.2
Description The issue is related to an XML external entity (XXE) vulnerability in the dashbuilder import facility. This vulnerability allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and potentially have other unspecified impacts by providing a crafted XML document.
Recommendations For versions prior to 6.1.2, update to version 6.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the ImportManagerImpl class in the org.jboss.dashboard.export package to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-1818

Affected Products

Red Hat Jboss Bpm Suite