The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxml2 | Aug 30, 2017 | Jan 21, 2015 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2015-006 | Aug 28, 2015 | Jan 21, 2015 |
| Apple Osx Libxml2 | — | Upgrade macOS to the latest versionApply OS X security update 2015-006 | Mar 29, 2016 | Jan 21, 2015 |
| Centos_linux | — | Upgrade libxml2-develUpgrade libxml2Upgrade libxml2-staticUpgrade libxml2-python | Dec 1, 2016 | Jan 21, 2015 |
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Jan 21, 2015 |
| Freebsd | — | Upgrade linux-c6-libxml2Upgrade libxml2Upgrade linux-f10-libxml2 | Dec 10, 2025 | May 6, 2014 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Jan 21, 2015 |
| Ibm Aix | — | Apply the fix or workaround for libxml2_advisory | Nov 30, 2017 | Jan 21, 2015 |
| Oracle Solaris | — | Upgrade runtime/python-27 to version 2.7.3-0.175.2.1.0.5.0 on Solaris 11.2Upgrade runtime/python-26 to version 2.6.8-0.175.2.1.0.5.0 on Solaris 11.2Upgrade library/libxml2 to version 2.9.1-0.175.2.1.0.4.0 on Solaris 11.2Upgrade library/python-2/libxml2-27 to version 2.9.1-0.175.2.1.0.4.0 on Solaris 11.2Upgrade library/python-2/libxml2-26 to version 2.9.1-0.175.2.1.0.4.0 on Solaris 11.2 | May 29, 2017 | Jan 21, 2015 |
| Oracle_linux | — | Upgrade libxml2-staticUpgrade libxml2-develUpgrade libxml2Upgrade libxml2-python | Oct 16, 2024 | Jan 21, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 6, 2014 |
| Suse | — | Upgrade python3-libxml2-pythonUpgrade libxml2Upgrade python-libxml2Upgrade libxml2-toolsUpgrade libxml2-pythonUpgrade libxml2-2Upgrade libxml2-develUpgrade ruby2.5-rubygem-nokogiriUpgrade libxml2-2-32bitUpgrade libxml2-docUpgrade sles12sp1-docker-imageUpgrade libxml2-devel-32bitUpgrade sles12-docker-imageUpgrade libxml2-32bitUpgrade libxml2-x86 | Dec 18, 2015 | Jan 21, 2015 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Jan 21, 2015 |
| Vmsa 2014 0012 | — | Upgrade VMware ESXi 5.0 to build number 2210222Upgrade VMware ESXi 5.1 to build number 2323236Upgrade VMware ESXi 5.5 to build number 2068190 | Oct 28, 2015 | Jan 21, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub