CVE-2016-8739

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
apachecxf
𝑥
≤ 3.0.11
apachecxf
3.1.0
apachecxf
3.1.1
apachecxf
3.1.2
apachecxf
3.1.3
apachecxf
3.1.4
apachecxf
3.1.5
apachecxf
3.1.6
apachecxf
3.1.7
apachecxf
3.1.8
𝑥
= Vulnerable software versions
References