PT-2023-10155 · Unknown · Java-Xmlbuilder

Xiaoyongwu

·

Published

2023-02-19

·

Updated

2024-05-17

·

CVE-2014-125087

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions java-xmlbuilder versions up to 1.1
Description A vulnerability was found in the software, rated as problematic. It affects some unknown functionality and leads to xml external entity reference.
Recommendations For versions up to 1.1, upgrade to version 1.2 to address this issue.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2014-125087
GHSA-3VRC-RRPW-R5PW

Affected Products

Java-Xmlbuilder