Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-9096
HistoryNov 08, 2017 - 4:29 p.m.

Xxe

2017-11-0816:29:00
PRIOn knowledge base
www.prio-n.com
6

8.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.5%

The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

CPENameOperatorVersion
itexteq7.0.0
itexteq7.0.1
itexteq7.0.2
itextlt5.5.12

8.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.5%