CVE-2014-8125 PUBLISHED CVSS 7.5 HIGH

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.

EPSS 0.96% · 76.3th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
0.96%
76.3th percentile

Affected Products

VendorProductVersions
Mavenorg.jbpm:jbpm-bpmn20
redhatdrools0
Mavenorg.drools:drools-core0
redhatjbpm0
n/an/an/a

Timeline

References

Open in Interactive Console →