First published: Wed Sep 19 2018(Updated: )
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | >=0.1<=1.18 | |
Oracle Business Process Management Suite | =12.1.3.0.0 | |
Oracle Business Process Management Suite | =12.2.1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-11761.
The severity of CVE-2018-11761 is high with a score of 7.5.
CVE-2018-11761 can lead to a denial of service attack.
Apache Tika versions from 0.1 to 1.18 and Oracle Business Process Management Suite versions 12.1.3.0.0 and 12.2.1.3.0 are affected by CVE-2018-11761.
The vulnerability CVE-2018-11761 can be mitigated by upgrading to Apache Tika version 1.19.