Lucene search

K
cve[email protected]CVE-2014-3530
HistoryJul 22, 2014 - 8:55 p.m.

CVE-2014-3530

2014-07-2220:55:01
CWE-200
web.nvd.nist.gov
37
cve-2014-3530
picketlink
jboss
xxe
entity reference expansion
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.5 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.2%

The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue.

Affected configurations

NVD
Node
redhatjboss_enterprise_application_platformMatch5.2.0
OR
redhatjboss_enterprise_application_platformMatch6.2.4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.5 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.2%