CVE-2014-6517
Public on 2014-10-15
Modified on 2014-10-16
Description
It was discovered that the StAX XML parser in the JAXP component in OpenJDK performed expansion of external parameter entities even when external entity substitution was disabled. A remote attacker could use this flaw to perform XML eXternal Entity (XXE) attack against applications using the StAX parser to parse untrusted XML documents.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | java-1.6.0-openjdk | 2014-10-16 | ALAS-2014-430 | Fixed |
Amazon Linux 1 | java-1.7.0-openjdk | 2014-10-16 | ALAS-2014-431 | Fixed |
Amazon Linux 1 | java-1.8.0-openjdk | 2014-10-16 | ALAS-2014-432 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
NVD | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:P/I:N/A:N |