In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
2018-09-19T14:29:00.287
2024-11-21T03:43:58.560
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | tika | ≤ 1.18 | Yes |
Application | oracle | business_process_management_suite | 12.1.3.0.0 | Yes |
Application | oracle | business_process_management_suite | 12.2.1.3.0 | Yes |