First published: Thu Feb 21 2013(Updated: )
The GateIn Portal Export / Import Gadget is vulnerable to XXE (XML eXternal Entity) attacks. If the XML provided to the import gadget contains an external XML entity, this XML entity will be resolved. A remote attacker who can access the import gadget could use this flaw to read files in the context of the user running the application server.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Enterprise Portal Platform | =5.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.