Check Point Reference: | CPAI-2014-1901 |
Date Published: | 29 Oct 2014 |
Severity: | High |
Last Updated: | Wednesday 29 October, 2014 |
Source: | Redhat RHSA-2014-1298 |
Industry Reference: | CVE-2014-3490 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Red Hat JBoss RESTEasy prior to 3.0.9 |
Vulnerability Description | An information disclosure vulnerability has been reported in Red Hat JBoss RESTEasy. This is due to an incorrectly configured XML parser accepting XML eXternal Entities (XXE) from the RESTEasy endpoint. A remote unauthenticated attacker may exploit this vulnerability on a web application powered by JBoss RESTEasy to disclose the contents of files via specially crafted XML documents. |
SmartView Tracker will log the following entries:
Attack Name: Application Servers Protection Violation.
Attack Information: Red Hat JBoss RESTEasy PARAMETER ENTITY XXE Information Disclosure