CVE-2017-9096

Updated on 08 Nov 2017

Severity

8.8 High severity

Details

CVSS score
8.8
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Overview

About vulnerability

The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

Details

Affected product:
cocoon , docx4j , flyingsaucer , itextpdf , jasperreports
Affected packages:
cocoon-axis-sample @ 2.3.0 (+239 more)
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

Fixes