First published: Thu May 18 2017(Updated: )
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise Application Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1451960 is considered critical due to its potential for DoS and SSRF attacks.
To fix REDHAT-BUG-1451960, upgrade your Red Hat JBoss EAP to the latest patched version that addresses this vulnerability.
REDHAT-BUG-1451960 can be exploited for denial of service (DoS), server-side request forgery (SSRF), and unauthorized file reading.
REDHAT-BUG-1451960 affects Red Hat JBoss EAP 7.0.5 and possibly other versions prior to the fix.
There is no reliable workaround for REDHAT-BUG-1451960; upgrading to a secure version is recommended.