CVE-2021-33813

HIGH

JDOM < 2.0.6 - XML External Entity Injection via SAXBuilder

Title source: llm
STIX 2.1

Description

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

References (17)

Core 17
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/hunterhacker/jdom/pull/188
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/hunterhacker/jdom/releases
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/06/msg00026.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/07/msg00012.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html
Exploit, Third Party Advisory x_refsource_misc
https://alephsecurity.com/vulns/aleph-2021003

Scores

CVSS v3 7.5
EPSS 0.0139
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-611
Status published
Products (9)
apache/solr 8.8.1
apache/solr 8.9
apache/tika 1.25
debian/debian_linux 9.0
fedoraproject/fedora 35
jdom/jdom < 2.0.6
oracle/communications_messaging_server 8.1
org.jdom/jdom 0Maven
org.jdom/jdom2 0 - 2.0.6.1Maven
Published Jun 16, 2021
Tracked Since Feb 18, 2026