PicketLink: XXE via insecure DocumentBuilderFactory usage
Published Jul 22, 2014
7.5
HIGHCVSS 2.0
EPSS 3.86%
Description
The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue.
Affected products
No data.
- 5.2.0
- 6.2.4
No data.
JBEWP 5 for RHEL 5
picketlink-federation-0:2.1.5-3_patch_01.ep5.el5
Fixed · RHSA-2014:0898
JBEWP 5 for RHEL 6
picketlink-federation-0:2.1.5-3_patch_01.el6_5
Fixed · RHSA-2014:0898
Red Hat JBoss BPMS 6.0
picketlink
Fixed · RHSA-2015:0234
Red Hat JBoss BRMS 6.0
picketlink
Fixed · RHSA-2015:0235
Red Hat JBoss Data Grid 6.4
picketlink
Fixed · RHSA-2015:0091
Red Hat JBoss Data Virtualization 6.0
picketlink
Fixed · RHSA-2015:0765
Red Hat JBoss Data Virtualization 6.1
n/a
Fixed · RHSA-2015:0675
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4
picketlink-federation-0:2.1.5-3_patch_01.ep5.el4
Fixed · RHSA-2014:0885
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5
picketlink-federation-0:2.1.5-3_patch_01.ep5.el5
Fixed · RHSA-2014:0885
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6
picketlink-federation-0:2.1.5-3_patch_01.el6_5
Fixed · RHSA-2014:0885
Red Hat JBoss Enterprise Application Platform 5.2
n/a
Fixed · RHSA-2014:0886
Red Hat JBoss Enterprise Application Platform 6.2
picketlink
Fixed · RHSA-2014:0884
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5
picketlink-federation-0:2.1.9-5.SP3_redhat_2.1.ep6.el5
Fixed · RHSA-2014:0883
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6
picketlink-federation-0:2.1.9-5.SP3_redhat_2.1.ep6.el6
Fixed · RHSA-2014:0883
Red Hat JBoss Fuse Service Works 6.0
picketlink
Fixed · RHSA-2015:0720
Red Hat JBoss Operations Network 3.2
n/a
Fixed · RHSA-2014:0910
Red Hat JBoss Portal 6.2
picketlink
Fixed · RHSA-2015:1009
Red Hat JBoss SOA Platform 5.3
picketlink
Fixed · RHSA-2015:1888
Red Hat JBoss Web Platform 5.2
n/a
Fixed · RHSA-2014:0897
Red Hat JBoss BRMS 5
picketlink
Will not fix
Red Hat JBoss Operations Network 3
picketlink
Affected
Red Hat JBoss Portal 5
picketlink
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEWP 5 for RHEL 5 | picketlink-federation-0:2.1.5-3_patch_01.ep5.el5 | Fixed | RHSA-2014:0898 |
| JBEWP 5 for RHEL 6 | picketlink-federation-0:2.1.5-3_patch_01.el6_5 | Fixed | RHSA-2014:0898 |
| Red Hat JBoss BPMS 6.0 | picketlink | Fixed | RHSA-2015:0234 |
| Red Hat JBoss BRMS 6.0 | picketlink | Fixed | RHSA-2015:0235 |
| Red Hat JBoss Data Grid 6.4 | picketlink | Fixed | RHSA-2015:0091 |
| Red Hat JBoss Data Virtualization 6.0 | picketlink | Fixed | RHSA-2015:0765 |
| Red Hat JBoss Data Virtualization 6.1 | n/a | Fixed | RHSA-2015:0675 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 | picketlink-federation-0:2.1.5-3_patch_01.ep5.el4 | Fixed | RHSA-2014:0885 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | picketlink-federation-0:2.1.5-3_patch_01.ep5.el5 | Fixed | RHSA-2014:0885 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | picketlink-federation-0:2.1.5-3_patch_01.el6_5 | Fixed | RHSA-2014:0885 |
| Red Hat JBoss Enterprise Application Platform 5.2 | n/a | Fixed | RHSA-2014:0886 |
| Red Hat JBoss Enterprise Application Platform 6.2 | picketlink | Fixed | RHSA-2014:0884 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 | picketlink-federation-0:2.1.9-5.SP3_redhat_2.1.ep6.el5 | Fixed | RHSA-2014:0883 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6 | picketlink-federation-0:2.1.9-5.SP3_redhat_2.1.ep6.el6 | Fixed | RHSA-2014:0883 |
| Red Hat JBoss Fuse Service Works 6.0 | picketlink | Fixed | RHSA-2015:0720 |
| Red Hat JBoss Operations Network 3.2 | n/a | Fixed | RHSA-2014:0910 |
| Red Hat JBoss Portal 6.2 | picketlink | Fixed | RHSA-2015:1009 |
| Red Hat JBoss SOA Platform 5.3 | picketlink | Fixed | RHSA-2015:1888 |
| Red Hat JBoss Web Platform 5.2 | n/a | Fixed | RHSA-2014:0897 |
| Red Hat JBoss BRMS 5 | picketlink | Will not fix | n/a |
| Red Hat JBoss Operations Network 3 | picketlink | Affected | n/a |
| Red Hat JBoss Portal 5 | picketlink | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw could allow remote, unauthenticated attackers to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks. All systems hosting PicketLink applications using SAML Identity Providers and Service Providers may be affected. It is strongly advised that anyone running an affected system applies patches to address this flaw.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.86% (0.03857) | 89.83th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.86% (0.03857) | 88.76th | v5 (v2026.06.15) |
| Mar 17, 2025 | 2.55% (0.02552) | 84.45th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.84% (0.00839) | 82.78th | v3 (v2023.03.01) |
| Mar 3, 2024 | 0.84% (0.00839) | 81.61th | v3 (v2023.03.01) |
| Jan 16, 2024 | 0.96% (0.00959) | 81.53th | v3 (v2023.03.01) |
| Oct 6, 2023 | 0.95% (0.00953) | 81.43th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.96% (0.00963) | 80.93th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.78% (0.03779) | 85.48th | v2 (v2022.01.01) |
| Feb 13, 2023 | 3.78% (0.03779) | 85.08th | v2 (v2022.01.01) |
| Feb 3, 2023 | 4.36% (0.04358) | 87.66th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.78% (0.03779) | 84.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.78% (0.03779) | 67.21th | v2 (v2022.01.01) |
References (21)
- http://rhn.redhat.com/errata/RHSA-2014-0883.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0884.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0885.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0886.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0091.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0675.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0720.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0765.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1888.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/60047 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60124 third-party-advisoryx_refsource_SECUNIA
- http://www.securitytracker.com/id/1030607 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2014-3530 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=1112987
- https://bugzilla.redhat.com/show_bug.cgi?id=1112987 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94700 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-2c9q-qwrc-f486 Advisory
- https://github.com/picketlink/picketlink/commit/8c78668e4f08cf3c4ed14d8a36d402dcf02cb057
- https://issues.jboss.org/browse/PLINK-509
- https://nvd.nist.gov/vuln/detail/CVE-2014-3530
- https://www.cve.org/CVERecord?id=CVE-2014-3530
Change history (0)
No recorded changes yet.