XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Drools | Redhat | * | 6.1.0 (including) |
Jbpm | Redhat | * | 6.1.0 (including) |
Red Hat JBoss BPMS 6.0 | RedHat | jbpm | * |
Red Hat JBoss BRMS 6.0 | RedHat | jbpm | * |