CVE-2017-7464
Summary
| CVE | CVE-2017-7464 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-27 12:29:00 UTC |
| Updated | 2023-02-12 23:29:00 UTC |
| Description | It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Enterprise Application Platform | 7.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RedHat JBoss Enterprise Application Platform XML External Entity Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| 1439520 – (CVE-2017-7464) CVE-2017-7464 JBoss: JAXP in EAP 7.0 allows info disclosure via XXE | CONFIRM | bugzilla.redhat.com | Issue Tracking, Mitigation, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.