It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/98546 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=1451960 | Issue Tracking Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2017-05-18T15:00:00
Updated: 2017-05-24T09:57:01
Reserved: 2017-04-05T00:00:00
Link: CVE-2017-7503
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-05-18T15:29:00.173
Modified: 2017-05-31T18:13:54.163
Link: CVE-2017-7503
JSON object: View
Redhat Information
No data.
CWE