CVE Vulnerabilities

CVE-2015-1818

Published: Aug 11, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.

Affected Software

NameVendorStart VersionEnd Version
Jboss_bpm_suiteRedhat*6.1.0 (including)
Red Hat JBoss BPMS 6.0RedHatdashbuilder*
Red Hat JBoss Data Virtualization 6.1RedHatdashbuilder*

References