Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36314
HistoryJul 11, 2022 - 6:22 a.m.

XML External Entity (XXE)

2022-07-1106:22:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
xml external entity
xxe
org.eclipse.lyo.oslc4j.core
oslc4j-jena-provider
vulnerability
dtd document loading
rdf/xml formats
remote attackers

EPSS

0.001

Percentile

47.2%

org.eclipse.lyo.oslc4j.core:oslc4j-jena-provider is vulnerable to XML external entity attack. Default initialization of createTransformer does not restrict DTD document loading when working with RDF/XML formats, which allows remote attackers to retrieve external DTD documents.

EPSS

0.001

Percentile

47.2%

Related for VERACODE:36314