Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21979
HistoryNov 19, 2019 - 3:15 a.m.

XML External Entities (XXE)

2019-11-1903:15:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
30

0.002 Low

EPSS

Percentile

59.9%

jackson-mapper-asl is vulnerable to XML external entity attacks. This vulnerability is similar to CVE-2016-3720 whereby the external DTD is not disabled, allowing an attacker to retrieve system files, or perform requests on behalf of the server using malicious XML documents.

References