CVE-2017-7503 | Security Details | Sonatype Guide
CVE-2017-7503
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
Published Jul 12, 2017
CVE-2017-7503 Security Details
CVE ID
CVE-2017-7503
CWE
CWE-611 Learn more about CWE-611
CVE Description
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
Published
Jul 12, 2017
CVSS Score & Severity
9.8 Critical
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.309%
Malware
malware
KEV Status
Not in KEV Catalog: No known exploits
Affected Ecosystems
affected
Source
National Vulnerability Database
References
Red Hat · Bugzilla