It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.jbpm.jbpm5:jbpmmigration(Maven) | 0 | N/A | N/A |
CVSS Metrics