CVE-2014-8125
XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files
XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
HIGH · CVSS 7.5
EPSS 0.00957
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0