The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.
CVSS Details
- CVSS 3.1 Base Score: 8.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-java/sun-jdk.Upgrade app-emulation/emul-linux-x86-java.Upgrade dev-java/sun-jre-bin. | Oct 30, 2017 | Feb 6, 2008 |
| Jre Vuln | — | Upgrade to the latest version of Oracle Java | May 29, 2014 | Feb 6, 2008 |
| Ubuntu | — | Upgrade sun-java6 | Nov 19, 2024 | Feb 6, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub