CVE-2017-7465
Summary
| CVE | CVE-2017-7465 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-27 16:29:00 UTC |
| Updated | 2023-02-12 23:30:00 UTC |
| Description | It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transform in JAXP requires the use of a 'javax.xml.transform.TransformerFactory'. If the FEATURE_SECURE_PROCESSING feature is set to 'true', it mitigates this vulnerability. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Enterprise Application Platform | 7.0.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1439980 – (CVE-2017-7465) CVE-2017-7465 JBoss: JAXP in EAP 7.0 allows RCE via XSL | CONFIRM | bugzilla.redhat.com | Issue Tracking, Mitigation, Third Party Advisory |
| Red Hat JBoss Enterprise Application Platform CVE-2017-7465 Remote Code Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.