CVE Vulnerabilities

CVE-2015-1818

Published: Aug 11, 2015 | Modified: Jan 05, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu

XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.

Affected Software

Name Vendor Start Version End Version
Jboss_bpm_suite Redhat * 6.1.0 (including)
Red Hat JBoss BPMS 6.0 RedHat dashbuilder *
Red Hat JBoss Data Virtualization 6.1 RedHat dashbuilder *

References