CVE-2016-4434

HIGH

Apache Tika < 1.13 - XML External Entity Injection via OOXML Spreadsheets and XMP Metadata

Title source: llm
STIX 2.1

Description

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/538500/100/0/threaded
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0272.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0249.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0248.html

Scores

CVSS v3 7.8
EPSS 0.0042
EPSS Percentile 61.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (2)
apache/tika 1.12
org.apache.tika/tika-core 0 - 1.13Maven
Published Sep 30, 2017
Tracked Since Feb 18, 2026