First published: Tue Jul 25 2017(Updated: )
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Decision Manager | =7.0 | |
Red Hat JBoss BPM Suite | =6.4 | |
Red Hat jBPM | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-7545 is considered to be critical due to its potential to allow unauthorized file access.
To fix CVE-2017-7545, you should upgrade to a patched version of the affected software, such as Red Hat Decision Manager 7.0 or jBPM 6.5.
CVE-2017-7545 affects users of Red Hat Decision Manager 7.0, jBoss BPM Suite 6.4, and jBPM 6.5.
CVE-2017-7545 is an XML external entity (XXE) vulnerability that can be exploited to read local files.
Yes, CVE-2017-7545 can potentially allow attackers to read sensitive data from local files on the server.