5
CVSSv2

CVE-2014-3481

Published: 07/07/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) prior to 6.2.4 enables entity expansion, which allows remote malicious users to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform

redhat jboss enterprise application platform 6.2.2

redhat jboss enterprise application platform 6.2.1

redhat jboss enterprise application platform 6.2.0

redhat jboss enterprise application platform 6.1.0

redhat jboss enterprise application platform 6.0.1

redhat jboss enterprise application platform 6.0.0

Vendor Advisories

It was found that the default context parameters as provided to RESTEasy deployments by JBoss EAP did not explicitly disable external entity expansion for RESTEasy A remote attacker could use this flaw to perform XML External Entity (XXE) attacks on RESTEasy applications accepting XML input ...