7.5
CVSSv2

CVE-2014-3530

Published: 22/07/2014 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote malicious users to read arbitrary code and possibly have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 6.2.4

redhat jboss enterprise application platform 5.2.0

Vendor Advisories

It was found that the implementation of the orgpicketlinkcommonutilDocumentUtilgetDocumentBuilderFactory() method provided a DocumentBuilderFactory that would expand entity references A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more a ...