Information disclosure in JBoss Enterprise Application Platform - CVE-2014-3481

 

Information disclosure in JBoss Enterprise Application Platform - CVE-2014-3481

Published: July 7, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41493
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2014-3481
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Red Hat Inc.
Affected software:
JBoss Enterprise Application Platform

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.


How to mitigate CVE-2014-3481

Install update from vendor's website.

Sources