Code Injection Vulnerability in JBoss EAP 7.0 by Red Hat
CVE-2017-7465
9CRITICAL
What is CVE-2017-7465?
The JAXP implementation in JBoss EAP 7.0 is susceptible to a code injection vulnerability due to insecure handling of XSLT transformations. An attacker could leverage this flaw by supplying crafted XSLT content, potentially resulting in the execution of arbitrary code on the server. To mitigate this risk, it is recommended to enable the 'FEATURE_SECURE_PROCESSING' feature when using the 'javax.xml.transform.TransformerFactory'. If left unprotected, the system may become vulnerable to exploitation.
Affected Version(s)
jboss
