PT-2018-8405 · Jbpm · Jbpmmigration

Published

2018-07-26

·

Updated

2022-05-13

·

CVE-2017-7545

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions jbpmmigration version 6.5
Description The XmlUtils class in jbpmmigration performs expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
Recommendations For jbpmmigration version 6.5, consider removing or restricting the use of the XmlUtils class until a patch is available. As a temporary workaround, avoid parsing untrusted XML files to minimize the risk of exploitation.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7545
GHSA-VC3X-72Q4-G3P5

Affected Products

Jbpmmigration