REDHAT-BUG-1856885: Medium severity OpenJDK JAXP vulnerability
A flaw was found in the way the XMLSchemaValidator class in the JAXP component of OpenJDK enforced the "use-grammar-pool-only" feature. A specially-crafted XML file could possibly use this flaw to manipulate with the validation process in certain cases.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1856885?
The severity of REDHAT-BUG-1856885 is categorized as moderate due to its potential impact on XML validation processes.
How do I fix REDHAT-BUG-1856885?
To fix REDHAT-BUG-1856885, update to the patched version of the OpenJDK JAXP component as provided by your software vendor.
What type of vulnerability is REDHAT-BUG-1856885?
REDHAT-BUG-1856885 is a validation flaw in the XMLSchemaValidator class of the OpenJDK JAXP component.
What software is affected by REDHAT-BUG-1856885?
REDHAT-BUG-1856885 affects the OpenJDK JAXP component.
Can REDHAT-BUG-1856885 be exploited remotely?
Yes, a specially-crafted XML file could potentially exploit REDHAT-BUG-1856885 to manipulate validation processes.