XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade derby | Jul 30, 2024 | Oct 3, 2016 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 28710939 for version 12.2.1.3.0. | Feb 27, 2019 | Oct 3, 2016 |
| Suse | — | Upgrade derby-javadocUpgrade derby | Oct 14, 2016 | Oct 3, 2016 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 3, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub