CVE-2014-8125

Description

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.957

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-8125 are fixed in Drools-drools-core 6.2.0Windows
Vulnerabilities CVE-2014-8125 are fixed in Jbpm - jbpm-bpmn2 6.2.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.4Windows
Vulnerabilities CVE-2014-8125 are affected in IBM Sterling B2B Integrator 6.0.0.7Windows
Vulnerabilities CVE-2014-8125 are fixed in Drools-drools-core for Linux 6.2.0Linux
Vulnerabilities CVE-2014-8125 are fixed in Jbpm - jbpm-bpmn2 for Linux 6.2.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234