CVE-2017-9096
—CVSS 3.0
8.8 high
EPSS
10%p95
Published
()
Modified
Description
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.
- Vendors
- itextpdf
- Products
- itext
- Weakness
- CWE-611
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.