Hide Forgot
It was found that Restlet is vulnerable to XXE (XML eXternal Entity) attacks. If a Restlet endpoint using XML transport, a user can submit a request containing an external XML entity. This XML entity will be resolved, allowing a remote attacker to read files in the context of the user running the application server.
External References: http://blog.restlet.com/2012/05/23/restlet-framework-2-1-rc5-and-2-0-14-released/ Statement: Not Vulnerable. This issue does not affect the versions of Restlet as shipped with various Red Hat products.