XXE attack in JBoss BRMS and Red Hat Process Automation Manager (formerly JBoss BPM Suite) - CVE-2015-3192
Published: August 15, 2016 / Updated: November 22, 2018
Vulnerability identifier: #VU312
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3192
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct XXe-attack on the target system.
The vulnerability exists in JBoss BPM Suite and BRMS. A remote attacker can cause denial of service conditions by submitting a specially crafted XML file that would cause out-of-memory errors when parsed.
Successful exploitation of this vulnerability may result in denial of service conditions on the target system.
The vulnerability exists in JBoss BPM Suite and BRMS. A remote attacker can cause denial of service conditions by submitting a specially crafted XML file that would cause out-of-memory errors when parsed.
Successful exploitation of this vulnerability may result in denial of service conditions on the target system.
Affected software
JBoss BRMS
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
watsonx.data
Fedora
Storage Copy Data Management
MobileFirst Platform
springframework
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
watsonx.data
Fedora
Storage Copy Data Management
MobileFirst Platform
springframework
How to mitigate CVE-2015-3192
Update your version at:
https://rhn.redhat.com/errata/RHSA-2016-1592.html
https://rhn.redhat.com/errata/RHSA-2016-1593.html
https://rhn.redhat.com/errata/RHSA-2016-1592.html
https://rhn.redhat.com/errata/RHSA-2016-1593.html
watsonx.data - update to 2.1
Storage Copy Data Management - update to 2.2.26.0
springframework - addressed in versions 3.2.14-1.fc21, 3.2.14-1.fc22
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
Storage Copy Data Management - update to 2.2.26.0
springframework - addressed in versions 3.2.14-1.fc21, 3.2.14-1.fc22
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031