5
CVSSv2

CVE-2013-6447

Published: 23/01/2014 Updated: 23/01/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and previous versions, as used in JBoss Web Framework Kit, allow remote malicious users to read arbitrary files and possibly have other impacts via a crafted XML file.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss seam 2 framework 2.3.0

redhat jboss seam 2 framework 2.0.0

redhat jboss seam 2 framework 2.1.0

redhat jboss seam 2 framework 2.1.1

redhat jboss seam 2 framework 2.3.1

redhat jboss seam 2 framework 2.0.1

redhat jboss seam 2 framework 2.0.2

redhat jboss seam 2 framework 2.2.0

redhat jboss seam 2 framework 2.2.1

redhat jboss seam 2 framework

redhat jboss seam 2 framework 2.0.3

redhat jboss seam 2 framework 2.1.2

redhat jboss seam 2 framework 2.2.2

Vendor Advisories

Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 231 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file ...