VDB
RHSA-2017:0179
RHSA-2017:0179
PUBLISHED
CVSS 5.400000095367432 MEDIUM
It was found that the parsing of XMP and other XML formats in PDF by Apache PDFBox would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Risk Scores
CVSS 3.0
5.400000095367432
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss A-MQ 6.3 | |
| Red Hat | Red Hat JBoss Fuse 6.3 |
Timeline
- Jan 19, 2017 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- May 13, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_0179.json advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-2175 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1343616 issue
- https://access.redhat.com/errata/RHSA-2017:0179 advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=6.3.0 advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.amq&downloadType=securityPatches&version=6.3.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1340396 issue
- https://access.redhat.com/security/cve/CVE-2016-2175 advisory
- https://www.cve.org/CVERecord?id=CVE-2016-2175 advisory
- https://access.redhat.com/security/cve/CVE-2016-4970 advisory
- https://www.cve.org/CVERecord?id=CVE-2016-4970 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-4970 advisory