XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Drools | Redhat | * | 6.1.0 (including) |
| Jbpm | Redhat | * | 6.1.0 (including) |
| Red Hat JBoss BPMS 6.0 | RedHat | jbpm | * |
| Red Hat JBoss BRMS 6.0 | RedHat | jbpm | * |