CVE-2014-3481
N/A
N/A
Summary
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://rhn.redhat.com/errata/RHSA-2014-0798.html
- http://www.securitytracker.com/id/1032017
- http://rhn.redhat.com/errata/RHSA-2015-0765.html
- http://rhn.redhat.com/errata/RHSA-2015-0675.html
- http://rhn.redhat.com/errata/RHSA-2015-0720.html
- http://rhn.redhat.com/errata/RHSA-2014-0797.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94939
- http://rhn.redhat.com/errata/RHSA-2014-0799.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1105242
References
- http://rhn.redhat.com/errata/RHSA-2014-0798.html
- http://www.securitytracker.com/id/1032017
- http://rhn.redhat.com/errata/RHSA-2015-0765.html
- http://rhn.redhat.com/errata/RHSA-2015-0675.html
- http://rhn.redhat.com/errata/RHSA-2015-0720.html
- http://rhn.redhat.com/errata/RHSA-2014-0797.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94939
- http://rhn.redhat.com/errata/RHSA-2014-0799.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1105242
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.