Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3651
HistoryMar 13, 2017 - 3:37 a.m.

Denial Of Service (DoS)

2017-03-1303:37:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.129 Low

EPSS

Percentile

95.5%

Apache Xerces2 is vulnerable to Denial-of-Service (DoS) attacks. The vulnerability exists in XMLScanner.java in Apache Xerces2 Java due to the way it handles malformed XML input. A malicious user can create a XML file with an invalid literal, or add a high surrogate character to cause the infinite loop when the XML file is parsed.

References