Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3891
HistoryApr 13, 2017 - 2:00 a.m.

XML External Entity (XXE) Injection

2017-04-1302:00:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.043 Low

EPSS

Percentile

92.3%

Apache batik is susceptible to denial of service (DoS) or file disclosure through XML external entities (XXE). The attacks are possible because it does not prevent dereferencing of XML external entities in the DTD and revealing the content of the target file in the output.

CPENameOperatorVersion
batik-domeq1.7
batik-domeq1.6.1
batik domle1.6-1

References