{"id":"CVE-2012-0818","description":"RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.","cvssScore":5,"cvssVersion":"2.0","cvssVector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","cvssMetrics":[{"version":"2.0","score":5,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-200"],"resolved":"MITIGATED-BY-RASP","published":"2012-11-23","lastModified":"2026-06-16","affectedProducts":[{"vendor":"redhat","product":"resteasy","versionEnd":"\u003c=2.3.0"},{"vendor":"redhat","product":"resteasy","version":"1.0.0"},{"vendor":"redhat","product":"resteasy","version":"1.0.1"},{"vendor":"redhat","product":"resteasy","version":"1.0.2"},{"vendor":"redhat","product":"resteasy","version":"1.1"},{"vendor":"redhat","product":"resteasy","version":"1.2"},{"vendor":"redhat","product":"resteasy","version":"2.0.0"},{"vendor":"redhat","product":"resteasy","version":"2.0.1"},{"vendor":"redhat","product":"resteasy","version":"2.1.0"},{"vendor":"redhat","product":"resteasy","version":"2.2.0"},{"vendor":"redhat","product":"resteasy","version":"2.2.1"},{"vendor":"redhat","product":"resteasy","version":"2.2.2"},{"vendor":"redhat","product":"resteasy","version":"2.2.3"}],"totalAffectedProducts":1,"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=785631","source":"patch-hint","tags":["bugzilla"]},{"url":"https://github.com/resteasy/resteasy/commit/71ace879cf92d323bfa4d3e88db0c3059109bbf6","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20200229045254/https://www.securityfocus.com/bid/51766","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20200229044434/http://www.securityfocus.com/bid/51748","source":"osv","tags":["WEB"]},{"url":"https://issues.jboss.org/browse/RESTEASY-637","source":"osv","tags":["WEB"]},{"url":"https://github.com/resteasy/Resteasy","source":"osv","tags":["PACKAGE"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72808","source":"osv","tags":["WEB"]},{"url":"https://access.redhat.com/security/cve/CVE-2012-0818","source":"osv","tags":["WEB"]},{"url":"https://access.redhat.com/errata/RHSA-2014:0372","source":"osv","tags":["WEB"]},{"url":"https://access.redhat.com/errata/RHSA-2014:0371","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"secure-rule-match","decidingReason":"Promoted to MITIGATED-BY-RASP (security rule): this CVE's description identifies a XXE vulnerability that can be mitigated by an ARMR xxe security rule at the JVM level, without requiring a CVE-specific patch. Matched by description (no specific CWE was assigned by NVD).","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.jboss.resteasy:resteasy-client"},{"rule":"patch-hint","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"References include candidate fix URL (bugzilla tier): https://bugzilla.redhat.com/show_bug.cgi?id=785631"},{"rule":"open-source-maven","stage":"disposition","outcome":"skipped"},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"Description mentions \"XXE\" — mitigable by an ARMR xxe security rule (CWE not assigned).","decisive":true},{"rule":"below-action-threshold","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit-published","stage":"disposition","outcome":"skipped"}],"patchHintUrl":"https://bugzilla.redhat.com/show_bug.cgi?id=785631","patchHintTier":"bugzilla","affectedProducts":[{"vendor":"redhat","product":"resteasy","isKnown":true,"cpe":"cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*","source":"yaml"}],"affectedPackages":[{"name":"org.jboss.resteasy:resteasy-client","introduced":"0","fixed":"2.3.1"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"],"ruleClass":"xxe"},"action":{"state":"available","type":"security-rule"},"review":{"state":"automated","basis":"inferred"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.03213,"percentile":0.87503},"ssvc":{"available":false},"patchHintUrl":"https://bugzilla.redhat.com/show_bug.cgi?id=785631","patchHintTier":"bugzilla"}