Total vulnerabilities in the database
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
Software | From | Fixed in |
---|---|---|
redhat / decision_manager | 7.0 | 7.0.x |
redhat / jboss_bpm_suite | 6.4 | 6.4.x |
redhat / jbpm | 6.5 | 6.5.x |
![]() |
- | 0.15.x |