XML injection (XXE) In java-1.8.0-openjdk
Description
It was discovered that the wsdlimport tool in the JAX-WS component of OpenJDK did not use secure XML parser settings when parsing WSDL XML documents. A specially crafted WSDL document could cause wsdlimport to use an excessive amount of CPU and memory, open connections to other hosts, or leak information.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | 1:1.8.0.141-1.b16.el7_3 | ||
rpm rhel7 | 1:1.7.0.151-2.6.11.1.el7_4 | ||
rpm rhel6 | 1:1.8.0.141-2.b16.el6_9 | ||
rpm rhel6 | 1:1.7.0.151-2.6.11.0.el6_9 |
Aliases
1. 2. 3.