{"id":"CVE-2014-8125","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-8125","summary":"Improper Input Validation in Drools and jBPM","details":"XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.","published":"2022-05-17T04:12:57Z","modified":"2024-12-07T05:39:36.704935Z","cvss":null,"epss":{"score":0.02636,"percentile":0.8482,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.drools:drools-core","fixedVersion":"6.2.0.Final"},{"ecosystem":"Maven","name":"org.jbpm:jbpm-bpmn2","fixedVersion":"6.2.0.Final"}],"fix":{"url":"https://github.com/droolsjbpm/drools/commit/c48464c3b246e6ef0d4cd0dbf67e83ccd532c6d3","label":"droolsjbpm/drools@c48464c"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-8125"},{"type":"WEB","url":"https://github.com/droolsjbpm/drools/commit/c48464c3b246e6ef0d4cd0dbf67e83ccd532c6d3"},{"type":"WEB","url":"https://github.com/droolsjbpm/jbpm/commit/713e8073ecf45623cfc5c918c5cbf700203f46e5"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1169553"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0850.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0851.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-07T05:39:36.704935Z"}}