7.5
CVSSv2

CVE-2015-1818

Published: 11/08/2015 Updated: 05/01/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite prior to 6.1.2 allows remote malicious users to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss bpm suite

Vendor Advisories

A flaw was found in the dashbuilder import facility: the DocumentBuilders instantiated in orgjbossdashboardexportImportManagerImpl did not disable external entities This could allow an attacker to perform a variety of XML External Entity (XXE) and Server-Side Request Forgery (SSRF) attacks ...