CVE-2018-11761: XEE
Published Sep 19, 2018
·Updated
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
Affected Software
4 affected componentsFixes available
redhat/tika<1.19
1.19
Apache Tika>=0.1<=1.18
Oracle Business Process Management Suite=12.1.3.0.0
Oracle Business Process Management Suite=12.2.1.3.0
Remediation
Event History
Sep 19, 2018
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeakness
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-11761.
2
What is the severity of CVE-2018-11761?
The severity of CVE-2018-11761 is high with a score of 7.5.
3
What is the impact of CVE-2018-11761?
CVE-2018-11761 can lead to a denial of service attack.
4
Which software versions are affected by CVE-2018-11761?
Apache Tika versions from 0.1 to 1.18 and Oracle Business Process Management Suite versions 12.1.3.0.0 and 12.2.1.3.0 are affected by CVE-2018-11761.
5
How can I mitigate the vulnerability CVE-2018-11761?
The vulnerability CVE-2018-11761 can be mitigated by upgrading to Apache Tika version 1.19.