CVE-2017-7503 | Security Details | Sonatype Guide

CVE-2017-7503

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

Published Jul 12, 2017

Red Hat · Bugzilla

CVE-2017-7503 Security Details

CVE ID
CVE-2017-7503

CWE
CWE-611 Learn more about CWE-611

CVE Description
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

Published
Jul 12, 2017

CVSS Score & Severity
9.8 Critical

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score
0.309%

Malware
malware

KEV Status
Not in KEV Catalog: No known exploits

Affected Ecosystems
affected

Source
National Vulnerability Database

References
Red Hat · Bugzilla