CVE-2015-0263: XEE
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0263?
CVE-2015-0263 is classified as a medium severity vulnerability due to its capability to allow remote attackers to read arbitrary files.
How do I fix CVE-2015-0263?
To fix CVE-2015-0263, upgrade Apache Camel to version 2.14.2 or 2.13.4 or later.
What impact does CVE-2015-0263 have on affected systems?
The impact of CVE-2015-0263 allows an attacker to exploit the vulnerability to potentially access sensitive files on the server.
Which versions of Apache Camel are affected by CVE-2015-0263?
CVE-2015-0263 affects Apache Camel versions before 2.13.4 and versions 2.14.0 and 2.14.1.
Is there a patch available for CVE-2015-0263?
Yes, patches are available in the form of updates to Apache Camel versions 2.13.4 and 2.14.2.