CVE-2017-7464: It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE fla
infovulnerability
security
Summary
CVE-2017-7464 is a vulnerability in JBoss EAP 7.0's XML parsing component that allows attackers to exploit XXE flaws (XXE is XML External Entity injection, a technique where malicious XML input tricks a parser into revealing sensitive data or accessing internal systems). An attacker who can provide XML content for the system to parse could cause denial of service (making the system unavailable), SSRF (server-side request forgery, where the server is tricked into making requests to unintended targets), or leak sensitive information.
Vulnerability Details
CVSS Score
7.5
EPSS (30-day exploit probability)
EPSS: 0.5%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2017-7464
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%