9.8
CVSSv3

CVE-2017-7503

Published: 18/05/2017 Updated: 31/05/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 7.0.5

Vendor Advisories

Synopsis Important: EAP Continuous Delivery Technical Preview Release 14 security update Type/Severity Security Advisory: Important Topic This is a security update for JBoss EAP Continuous Delivery 140Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
It was found that the Red Hat JBoss EAP 705 implementation of javaxxmltransformTransformerFactory is vulnerable to XXE An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed ...