Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25614
HistoryJun 05, 2020 - 5:45 a.m.

XML External Entity (XXE)

2020-06-0505:45:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.017 Low

EPSS

Percentile

87.7%

PostgreSQL JDBC Driver is vulnerable to XML external entity attacks. External DTDs are not disabled by default, allowing an attacker to perform XXE attacks and perform request on behalf of the server or retrieve system files via a malicious XML document.

References