Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3925
HistoryApr 19, 2017 - 1:00 a.m.

Information Disclosure Through An External XML Entity (XXE) Vulnerability

2017-04-1901:00:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.002 Low

EPSS

Percentile

54.3%

Apache Batik is vulnerable to information disclosure through an external XML entity (XXE) vulnerability. The vulnerability is possible because it does not properly validate the file when handling a maliciously formed SVG file. Using this flaw, attackers can gain access to confidential information and private files. The XXE can also be used to trigger an XML entity expansion to consume all the system’s memory, crashing it and causing a denial of service (DoS) condition.

CPENameOperatorVersion
batik domle1.6-1
batik-domle1.8