Code Injection Vulnerability in JBoss EAP 7.0 by Red Hat
CVE-2017-7465

9CRITICAL

Key Information:

Vendor

[unknown]

Status
Vendor
CVE Published:
27 June 2018

What is CVE-2017-7465?

The JAXP implementation in JBoss EAP 7.0 is susceptible to a code injection vulnerability due to insecure handling of XSLT transformations. An attacker could leverage this flaw by supplying crafted XSLT content, potentially resulting in the execution of arbitrary code on the server. To mitigate this risk, it is recommended to enable the 'FEATURE_SECURE_PROCESSING' feature when using the 'javax.xml.transform.TransformerFactory'. If left unprotected, the system may become vulnerable to exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

jboss

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.