XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jboss_bpm_suite | Redhat | * | 6.1.0 (including) |
Red Hat JBoss BPMS 6.0 | RedHat | dashbuilder | * |
Red Hat JBoss Data Virtualization 6.1 | RedHat | dashbuilder | * |