First published: Wed Feb 06 2008(Updated: )
The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JRE | <=1.6.0 | |
Sun JDK | =1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.