Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35403
HistoryMay 06, 2022 - 5:01 a.m.

XML External Entity (XXE)

2022-05-0605:01:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
59
xml
external entity
jena-core
rdfxmlparser
vulnerability
security

EPSS

0.029

Percentile

90.8%

jena-core is vulnerable to XML external entity attacks. The RDFXMLParser function of RDFXMLParser.java does not properly disable the access to external entities, allowing an attacker to submit a malicious XML document to perform requests on behalf of the server.

EPSS

0.029

Percentile

90.8%