PT-2015-5457 · Red Hat · Red Hat Jboss Bpm Suite
David Jorm
·
Published
2015-08-11
·
Updated
2018-01-05
·
CVE-2015-1818
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat JBoss BPM Suite versions prior to 6.1.2
Description
The issue is related to an XML external entity (XXE) vulnerability in the dashbuilder import facility. This vulnerability allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and potentially have other unspecified impacts by providing a crafted XML document.
Recommendations
For versions prior to 6.1.2, update to version 6.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the ImportManagerImpl class in the org.jboss.dashboard.export package to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat Jboss Bpm Suite