cvedb.io
CVE-2017-7545
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2018-07-26T15:29:00.307 · Last modified 2026-06-17T01:24:34.780

Summary

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.

Affected products

redhat — decision_manager

Does this affect you?

Add your gear to cvedb and we'll alert you only when redhat ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.