The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted external XML entity in an XML document, aka an XML Entity Expansion (XEE) attack.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.osvdb.org/91121 | vdb entry |
http://secunia.com/advisories/52552 | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=913340 | |
http://rhn.redhat.com/errata/RHSA-2013-0613.html | vendor advisory |