XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
| Software | From | Fixed in |
|---|---|---|
| redhat / jbpm | - | 6.1.0.x |
| redhat / drools | - | 6.1.0.x |
org.drools / drools-core
|
- | 6.2.0.Final |
org.jbpm / jbpm-bpmn2
|
- | 6.2.0.Final |