CVE-2013-6447: Red Hat JBoss Seam 2 Framework

Medium severity, CVSS 5.0. EPSS: 2.7% chance of exploitation in the next 30 days.

Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file.

Affected products

  • Red Hat JBoss Seam 2 Framework: up to and including 2.3.1; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.1.0 only; …

Published 2014-01-23. Last modified 2026-06-17.