Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-5245

EPSS 0.95% · P76
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-5245

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
RESTEasy ‘readFrom ’函数安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
RESTEasy 2.3.2之前版本中的providers.jaxb.JAXBXmlTypeProvider中的‘readFrom ’函数中存在漏洞。远程攻击者利用该漏洞通过XML Binding (JAXB)输入的Java Architecture中的外部实体引用,读取任意文件。又名XML外部实体注入攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-5245

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-5245

Please Login to view more intelligence information

Same Patch Batch · n/a · 2012-11-23 · 32 CVEs total

CVE-2012-3516Xen ‘GNTTABOP_swap_grant_ref’拒绝服务漏洞
CVE-2012-5759IBM WebSphere DataPower XC10 权限许可和访问控制漏洞
CVE-2012-5758IBM WebSphere DataPower XC10 Appliance接口设计漏洞
CVE-2012-5756IBM WebSphere DataPower XC10 Appliance 加密问题漏洞
CVE-2012-5173BIGACE Web CMS 会话固定漏洞
CVE-2010-1330JRuby 正则表达式引擎中跨站脚本漏洞
CVE-2012-6036Xen Transcendent Memory 拒绝服务漏洞
CVE-2012-6035Xen Transcendent Memory 拒绝服务漏洞
CVE-2012-6034Xen Transcendent Memory 任意代码漏洞
CVE-2012-6033Xen Transcendent Memory ‘do_tmem_control’函数安全漏洞
CVE-2012-6032Xen Transcendent Memory 整数溢出漏洞
CVE-2012-6031Xen Transcendent Memory ‘do_tmem_get’函数拒绝服务漏洞
CVE-2012-6030Xen Transcendent Memory ‘do_tmem_op’函数拒绝服务漏洞
CVE-2012-4602TCExam 多个跨站脚本漏洞
CVE-2012-4601TCExam 多个SQL注入漏洞
CVE-2012-4411Xen 信息泄露漏洞
CVE-2011-1096Red Hat JBossWS 加密问题漏洞
CVE-2012-3515Xen 输入验证错误漏洞
CVE-2012-3498Xen ‘PHYSDEVOP_map_pirq’索引拒绝服务漏洞
CVE-2012-3497Xen ‘TMEM hypercall’多个安全漏洞

Showing top 20 of 32 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2011-5245

No comments yet


Leave a comment