← Vulnerability feed

Vulnerability record · CVE-2011-5245 · published 23 November 2012

CVE-2011-5245: Redhat resteasy information exposure vulnerability

Redhat · Resteasy

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.

5.0 CVSS 2.0 Medium EPSS 3.2% · top 12.3% CWE-200 · Information exposure
5.0CVSS 2.0 base score
3.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
38References
16 Jun 2026Last modified by NVD

Description

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rhn.redhat.com/errata/RHSA-2012-0441.html
http://rhn.redhat.com/errata/RHSA-2012-0519.html
http://rhn.redhat.com/errata/RHSA-2012-1056.html
http://rhn.redhat.com/errata/RHSA-2012-1057.html
http://rhn.redhat.com/errata/RHSA-2012-1058.html
http://rhn.redhat.com/errata/RHSA-2012-1059.html
http://rhn.redhat.com/errata/RHSA-2012-1125.html
http://rhn.redhat.com/errata/RHSA-2014-0371.html
http://rhn.redhat.com/errata/RHSA-2014-0372.html
http://secunia.com/advisories/47832 Vendor Advisory
http://secunia.com/advisories/50084 Vendor Advisory
http://secunia.com/advisories/57716
http://secunia.com/advisories/57719
http://www.osvdb.org/78680
http://www.securityfocus.com/bid/51766
https://bugzilla.redhat.com/show_bug.cgi?id=785631
https://exchange.xforce.ibmcloud.com/vulnerabilities/72808
https://issues.jboss.org/browse/RESTEASY-647 Patch
https://issues.jboss.org/browse/RESTEASY/fixforversion/12318708
http://rhn.redhat.com/errata/RHSA-2012-0441.html
http://rhn.redhat.com/errata/RHSA-2012-0519.html
http://rhn.redhat.com/errata/RHSA-2012-1056.html
http://rhn.redhat.com/errata/RHSA-2012-1057.html
http://rhn.redhat.com/errata/RHSA-2012-1058.html
http://rhn.redhat.com/errata/RHSA-2012-1059.html
http://rhn.redhat.com/errata/RHSA-2012-1125.html
http://rhn.redhat.com/errata/RHSA-2014-0371.html
http://rhn.redhat.com/errata/RHSA-2014-0372.html
http://secunia.com/advisories/47832 Vendor Advisory
http://secunia.com/advisories/50084 Vendor Advisory
http://secunia.com/advisories/57716
http://secunia.com/advisories/57719
http://www.osvdb.org/78680
http://www.securityfocus.com/bid/51766
https://bugzilla.redhat.com/show_bug.cgi?id=785631
https://exchange.xforce.ibmcloud.com/vulnerabilities/72808
https://issues.jboss.org/browse/RESTEASY-647 Patch
https://issues.jboss.org/browse/RESTEASY/fixforversion/12318708

Track CVE-2011-5245 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2016-9606Redhat resteasy improper input validation vulnerabilityJBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted dat…EPSS 6.0%8.1CVE-2018-1051Redhat resteasy improper input validation vulnerabilityIt was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…EPSS 1.3%7.5CVE-2020-14326Redhat integration camel k uncontrolled resource consumption vulnerabilityA vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with…EPSS 1.2%7.5CVE-2020-1695Redhat resteasy improper input validation vulnerabilityA flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input v…EPSS 2.0%7.5CVE-2016-6346Redhat resteasy vulnerabilityRESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.EPSS 5.6%7.5CVE-2014-3490Redhat jboss enterprise application platform vulnerabilityRESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external…EPSS 4.6%6.5CVE-2016-6345Redhat resteasy information exposure vulnerabilityRESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.EPSS 1.8%6.4CVE-2014-7839Redhat resteasy improper input validation vulnerabilityDocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2011-5245), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.