{"id":"CVE-2017-7545","aliases":["GHSA-vc3x-72q4-g3p5"],"url":"https://o3.security/vulnerability/CVE-2017-7545","summary":"XML External Entity Reference in jbpmmigration","details":"It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.","published":"2018-07-26T15:29:00.307Z","modified":"2026-07-28T14:28:08.242637Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jbpm.jbpm5:jbpmmigration","fixedVersion":null}],"fix":{"url":"https://github.com/kiegroup/jbpm-designer/commit/a143f3b92a6a5a527d929d68c02a0c5d914ab81d","label":"kiegroup/jbpm-designer@a143f3b"},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/102179"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3354"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3355"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7545"},{"type":"FIX","url":"https://github.com/kiegroup/jbpm-designer/commit/a143f3b92a6a5a527d929d68c02a0c5d914ab81d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-28T14:28:08.242637Z"}}