PT-2018-8384 · Red Hat · Jboss Eap

Published

2018-07-27

·

Updated

2023-02-12

·

CVE-2017-7464

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JBoss EAP version 7.0
Description The JAXP implementation used for SAX and DOM parsing in JBoss EAP is susceptible to certain XXE flaws. This could allow an attacker to cause a denial of service, server-side request forgery, or information disclosure if they can provide XML content for parsing.
Recommendations For JBoss EAP version 7.0, update the JAXP implementation to a version that is not vulnerable to XXE flaws.

Fix

DoS

XXE

Weakness Enumeration

Related Identifiers

CVE-2017-7464

Affected Products

Jboss Eap