# CVE-2017-7503

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

Published Jul 12, 2017

[Red Hat · Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7503)

## CVE-2017-7503 Security Details

**CVE ID**  
CVE-2017-7503

**CWE**  
CWE-611 [Learn more about CWE-611](https://cwe.mitre.org/data/definitions/611.html)

**CVE Description**  
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

**Published**  
Jul 12, 2017

**CVSS Score & Severity**  
9.8 Critical

**CVSS Vector**  
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**EPSS Score**  
0.309%

**Malware**  
malware

**KEV Status**  
Not in KEV Catalog: No known exploits

**Affected Ecosystems**  
affected

**Source**  
National Vulnerability Database

**References**  
[Red Hat · Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7503)
