CVE-2016-4216: High severity adobe xmp toolkit vulnerability
Published Jul 13, 2016
·Updated
XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
1 affected component
Adobe Xmp Toolkit Java<=5.1.2
Remediation
Event History
Jul 13, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4216?
CVE-2016-4216 has a medium severity level due to potential unauthorized file access.
2
How do I fix CVE-2016-4216?
To remediate CVE-2016-4216, upgrade to Adobe XMP Toolkit for Java version 5.1.3 or later.
3
What types of attacks are possible with CVE-2016-4216?
CVE-2016-4216 allows remote attackers to perform XML External Entity (XXE) attacks which can lead to unauthorized file read.
4
Which versions of Adobe XMP Toolkit are affected by CVE-2016-4216?
CVE-2016-4216 affects Adobe XMP Toolkit for Java versions before 5.1.3.
5
Is user interaction required to exploit CVE-2016-4216?
No, exploitation of CVE-2016-4216 can occur remotely without user interaction.