Lucene search

K
cve[email protected]CVE-2015-1818
HistoryAug 11, 2015 - 2:59 p.m.

CVE-2015-1818

2015-08-1114:59:00
web.nvd.nist.gov
21
cve-2015-1818
xxe vulnerability
red hat jboss bpm suite
documentbuilders
ssrf
nvd
security vulnerability
xml external entity

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

79.2%

XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.

Affected configurations

NVD
Node
redhatjboss_bpm_suiteRange6.1.0

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

79.2%

Related for CVE-2015-1818