Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade woodstox-core-javadocUpgrade woodstox-core | Feb 21, 2024 | Sep 16, 2022 |
| Debian | — | No solution exists | May 15, 2025 | Sep 16, 2022 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 35227385 for version 14.1.1.0.0. | Jul 19, 2023 | Sep 16, 2022 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Sep 16, 2022 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Sep 16, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub