QID 980332

QID 980332: Java (maven) Security Update for org.apache.xmlbeans:xmlbeans (GHSA-mw3r-pfmg-xp92)

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to refer to GHSA-mw3r-pfmg-xp92 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980332

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mw3r-pfmg-xp92 org.apache.xmlbeans:xmlbeans URL Logo github.com/advisories/GHSA-mw3r-pfmg-xp92