Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3172
HistoryDec 23, 2016 - 4:04 a.m.

XML External Entity (XXE)

2016-12-2304:04:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.006 Low

EPSS

Percentile

77.6%

Apache CXF JAX-RS is vulnerable to XML eternal entity (XXE) attacks. The Atom MessageBodyReaders use Apache Abdera Parser to parse Atom feeds or Entries, with this Parser expanding XML entities by default. This represents a major XXE risk.

References