VDB

RHSA-2017%3A0179

RHSA-2017%3A0179 PUBLISHED CVSS 5.400000095367432 MEDIUM

It was found that the parsing of XMP and other XML formats in PDF by Apache PDFBox would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Risk Scores

CVSS 3.0
5.400000095367432
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

Affected Products

VendorProductVersions
Red HatRed Hat JBoss A-MQ 6.3
Red HatRed Hat JBoss Fuse 6.3

Timeline

  • Jan 19, 2017 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • May 13, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›