PT-2018-9485 · Dom4J+3 · Dom4J+3

Published

2018-07-01

·

Updated

2026-05-19

·

CVE-2018-1000632

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions dom4j versions prior to 2.1.1
Description The issue is related to an XML Injection vulnerability in the Class: Element, specifically in the addElement and addAttribute methods. This can result in an attacker tampering with XML documents through XML injection, which appears to be exploitable via an attacker specifying attributes or elements in the XML document.
Recommendations For dom4j versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the addElement and addAttribute methods in the Element class until a patch is available. Restrict access to the vulnerable Class: Element to minimize the risk of exploitation. Avoid using the addElement and addAttribute methods in the affected XML documents until the issue is resolved.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2025-11250
CVE-2018-1000632
DLA-1517-1
GHSA-6PCC-3RFX-4GPM
MGASA-2019-0077
OPENSUSE-SU-2018:4045-1
OPENSUSE-SU-2018_2931-1
OPENSUSE-SU-2018_3998-1
OPENSUSE-SU-2024:10724-1
RHSA-2019:0364
RHSA-2019:0365
RHSA-2019:1159
RHSA-2019:1160
RHSA-2019:1161
RHSA-2019:3172
ROSA-SA-2024-2454
SUSE-SU-2018:2861-1
SUSE-SU-2018:2863-1
SUSE-SU-2018:3424-1
SUSE-SU-2018_3424-1
SUSE-SU-2018_3908-1
USN-4619-1

Affected Products

Red Os
Suse
Ubuntu
Dom4J