5
CVSSv2

CVE-2011-5245

Published: 23/11/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy prior to 2.3.2 allows remote malicious users to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat resteasy 2.0.1

redhat resteasy 2.0.0

redhat resteasy 2.2.1

redhat resteasy 2.2.0

redhat resteasy 2.1.0

redhat resteasy 1.0.0

redhat resteasy 2.2.3

redhat resteasy 2.2.2

redhat resteasy 1.0.2

redhat resteasy 1.0.1

redhat resteasy

redhat resteasy 2.3.0

redhat resteasy 1.2

redhat resteasy 1.1

Vendor Advisories

Synopsis Moderate: resteasy security update Type/Severity Security Advisory: Moderate Topic Updated resteasy packages that fix one security issue are now available forJBoss Enterprise Application Platform 512 for Red Hat Enterprise Linux 4,5, and 6The Red Hat Security Response Team has rated this update ...
Synopsis Moderate: resteasy security update Type/Severity Security Advisory: Moderate Topic Updated resteasy packages that fix one security issue are now available forJBoss Enterprise Web Platform 512 for Red Hat Enterprise Linux 4, 5, and6The Red Hat Security Response Team has rated this update as havin ...
Synopsis Moderate: Red Hat Storage Console 21 security update Type/Severity Security Advisory: Moderate Topic Updated Red Hat Storage Console packages that fix one security issue,various bugs, and add enhancements are now available for Red Hat StorageServer 21The Red Hat Security Response Team has rated ...
Synopsis Moderate: rhevm security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated rhevm packages that fix one security issue and various bugs are nowavailableThe Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerability Scoring ...