Red Hat JBoss Web Framework Kit XML External Entity Information Disclosure Vulnerability
BID:65049
Info
Red Hat JBoss Web Framework Kit XML External Entity Information Disclosure Vulnerability
| Bugtraq ID: | 65049 |
| Class: | Design Error |
| CVE: |
CVE-2013-6448 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2013 12:00AM |
| Updated: | Dec 18 2013 12:00AM |
| Credit: | Jon Passki, Coverity SRL. |
| Vulnerable: |
Redhat JBoss Web Framework Kit 2.4 |
| Not Vulnerable: | |
Discussion
Red Hat JBoss Web Framework Kit XML External Entity Information Disclosure Vulnerability
Red Hat JBoss Web Framework Kit is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
Red Hat JBoss Web Framework Kit is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
Exploit / POC
Red Hat JBoss Web Framework Kit XML External Entity Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Red Hat JBoss Web Framework Kit XML External Entity Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Red Hat JBoss Web Framework Kit XML External Entity Information Disclosure Vulnerability
References:
References: