Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
23 May 2025, 17:54
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:redhat:jboss_middleware:1:*:*:*:*:*:*:* cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:* |
|
First Time |
Redhat jboss Middleware
Redhat Xstream xstream Xstream |
|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183180.html - Third Party Advisory, Broken Link | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183208.html - Third Party Advisory, Broken Link |
Information
Published : 2016-05-17 14:08
Updated : 2025-05-23 17:54
NVD link : CVE-2016-3674
Mitre link : CVE-2016-3674
CVE.ORG link : CVE-2016-3674
JSON object : View
Products Affected
redhat
- jboss_middleware
fedoraproject
- fedora
xstream
- xstream
debian
- debian_linux
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor