5
CVSSv2

CVE-2013-0315

Published: 12/04/2013 Updated: 15/04/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote malicious users to read arbitrary files via a crafted external XML entity in an XML document, aka an XML Entity Expansion (XEE) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise portal platform 5.2.2

Vendor Advisories

Synopsis Important: JBoss Enterprise Portal Platform 522 security update Type/Severity Security Advisory: Important Topic An update for the GateIn Portal component in JBoss Enterprise PortalPlatform 522 that fixes two security issues is now available from theRed Hat Customer PortalThe Red Hat Security ...