Security Advisory

CVE-2017-7503

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-05-18 15:00:00
Last updated 2024-08-05 16:04:11
Assigner redhat
State PUBLISHED

Description

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.