CVE-2015-1833

Apache Jackrabbit XML External Entity Injection via WebDAV Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-1833. PoCs published by Mikhail Egorov.

AI-analyzed exploit summary This exploit demonstrates an XXE (XML External Entity) vulnerability in Apache Jackrabbit WebDAV (CVE-2015-1833). It includes three techniques (inb1, inb2, oob) to exfiltrate data via crafted PROPPATCH/PROPFIND requests or out-of-band FTP.

Description

XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.

Exploits (1)

exploitdb WORKING POC
by Mikhail Egorov · pythonwebappsjava
https://www.exploit-db.com/exploits/37110

This exploit demonstrates an XXE (XML External Entity) vulnerability in Apache Jackrabbit WebDAV (CVE-2015-1833). It includes three techniques (inb1, inb2, oob) to exfiltrate data via crafted PROPPATCH/PROPFIND requests or out-of-band FTP.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Apache Jackrabbit WebDAV (versions prior to 2.10.1), Apache Sling, Adobe AEM
No auth needed
Prerequisites: Network access to the target WebDAV endpoint · For inb2/oob techniques, a visible IP for callback communication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3298
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74761
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37110/
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535582/100/0/threaded
Vendor Advisory x_refsource_confirm
https://issues.apache.org/jira/browse/JCR-3883

Scores

EPSS 0.3103
EPSS Percentile 96.9%

Details

CWE
CWE-20
Status published
Products (28)
apache/jackrabbit 2.2.0
apache/jackrabbit 2.2.1
apache/jackrabbit 2.2.2
apache/jackrabbit 2.2.4
apache/jackrabbit 2.2.5
apache/jackrabbit 2.2.7
apache/jackrabbit 2.2.8
apache/jackrabbit 2.2.9
apache/jackrabbit 2.2.10
apache/jackrabbit 2.2.11
... and 18 more
Published May 29, 2015
Tracked Since Feb 18, 2026