7.5
CVSSv2

CVE-2014-8125

Published: 21/04/2015 Updated: 26/05/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

XML external entity (XXE) vulnerability in Drools and jBPM prior to 6.2.0 allows remote malicious users to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat drools

redhat jbpm

Vendor Advisories

It was discovered that the jBPM runtime performed expansion of external parameter entities while executing BPMN2 files A remote attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XML eXternal Entity (XXE) attacks ...