First published: Fri Jul 27 2018(Updated: )
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise Application Platform | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7464 is considered significant due to its potential for DoS, SSRF, or information disclosure.
To fix CVE-2017-7464, update to a patched version of JBoss EAP that addresses the XXE vulnerabilities.
CVE-2017-7464 can facilitate DoS, SSRF, and information disclosure attacks.
CVE-2017-7464 affects JBoss EAP version 7.0.
XXE stands for XML External Entity, a vulnerability that can lead to security breaches through XML input processing.