ZeroHour

CVE-2017-7503

CVSS 3.0
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

Vendors
redhat
Products
jboss enterprise application platform
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.