CVE-2021-39239: XML External Entity (XXE) vulnerability
Published Sep 16, 2021
·Updated
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
Affected Software
3 affected components
Apache Jena<=4.1.0
IBM Engineering Requirements Management DOORS and DOORS Web Access<=9.7.2.1 - 9.7.2.11
IBM Engineering Requirements Management DOORS and DOORS Web Access<=9.6.1.1 - 9.6.1.13
Event History
Sep 16, 2021
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 6, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-39239?
The severity of CVE-2021-39239 is high, with a severity value of 7.5.
2
What is the vulnerability in Apache Jena?
The vulnerability in Apache Jena is an XML External Entities (XXE) vulnerability.
3
Which versions of Apache Jena are affected by CVE-2021-39239?
Versions up to 4.1.0 of Apache Jena are affected by CVE-2021-39239.
4
How can an attacker exploit CVE-2021-39239?
An attacker can exploit CVE-2021-39239 by executing XML External Entities (XXE) to expose the contents of local files to a remote server.
5
Is there a fix available for CVE-2021-39239?
Yes, upgrading to a version beyond 4.1.0 of Apache Jena will provide a fix for CVE-2021-39239.