AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2017-7503

CRITICAL · CVSS 9.8 EPSS 2.01%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-05-18 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2017-7503
Severity
CRITICAL
CVSS
9.8
EPSS
2.01%
Java

Original Filing — NVD Description

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.