PT-2017-17776 · Red Hat · Red Hat Jboss Eap

Jason Shepherd

·

Published

2017-05-18

·

Updated

2017-05-31

·

CVE-2017-7503

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Red Hat JBoss EAP version 7.0.5
Description The issue is related to the implementation of javax.xml.transform.TransformerFactory in Red Hat JBoss EAP, which is vulnerable to XML External Entity (XXE) attacks. This could allow an attacker to launch Denial of Service (DoS) or Server-Side Request Forgery (SSRF) attacks, or read files from the server where EAP is deployed.
Recommendations For Red Hat JBoss EAP version 7.0.5, update the javax.xml.transform.TransformerFactory implementation to prevent XXE attacks. As a temporary workaround, consider restricting access to sensitive files on the server and implementing network controls to minimize the risk of SSRF attacks.

Fix

DoS

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7503

Affected Products

Red Hat Jboss Eap