CVE-2021-33813: XEE
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jdom:jdomto a version that resolves this vulnerability.Fixed in 2.0.6.1 - Configuration
As a workaround for the XXE issue, call `builder.setExpandEntities(false)` so external entities are not expanded.
JDOM SAXBuilder setExpandEntities(false) = false
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-33813.
What is the severity level of CVE-2021-33813?
CVE-2021-33813 has a severity level of high.
How can I exploit this vulnerability?
This vulnerability can be exploited by sending a specially-crafted HTTP request.
How can I fix CVE-2021-33813 in IBM Sterling Secure Proxy 6.0.3?
You can fix CVE-2021-33813 in IBM Sterling Secure Proxy 6.0.3 by applying the patch available at [IBM Fix Central](https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Other+software&product=ibm/Other+software/Sterling+Secure+Proxy&release=6.0.3.0&platform=All&function=all).
How can I fix CVE-2021-33813 in IBM Sterling Secure Proxy 6.1.0?
You can fix CVE-2021-33813 in IBM Sterling Secure Proxy 6.1.0 by applying the patch available at [IBM Fix Central](https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Other+software&product=ibm/Other+software/Sterling+Secure+Proxy&release=6.1.0.0&platform=All&function=all).