CVE Database
/

CVE-2016-8739

Back to search

CVE-2016-8739

Published: Aug 10, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.

VendorProductVersions

Apache Software Foundation

Apache CXF

affected
prior to 3.0.12
affected
3.1.x prior to 3.1.9

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now