CVE-2017-7503: Red Hat JBoss Enterprise Application Platform

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 7.0.5 only

Published 2017-05-18. Last modified 2026-06-17.