Medium severity6.5NVD Advisory· Published Jul 26, 2018· Updated Jun 17, 2026
CVE-2017-7545
CVE-2017-7545
Description
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jbpm.jbpm5:jbpmmigrationMaven | <= 0.15 | — |
Affected products
2- KIE/jbpm-designerv5Range: 6.5
Patches
Vulnerability mechanics
References
8- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchVendor AdvisoryWEB
- github.com/kiegroup/jbpm-designer/commit/a143f3b92a6a5a527d929d68c02a0c5d914ab81dnvdPatchThird Party AdvisoryWEB
- www.securityfocus.com/bid/102179nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2017:3354nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2017:3355nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-vc3x-72q4-g3p5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-7545ghsaADVISORY
- bugzilla.redhat.com/show_bug.cgighsaWEB
News mentions
0No linked articles in our index yet.