Releases201
Frequency3 weeks 2 days
Last Release
Stars1.73K
a Business Process Management (BPM) Suite

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.