7.5
CVSSv2

CVE-2016-2175

Published: 01/06/2016 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache PDFBox prior to 1.8.12 and 2.x prior to 2.0.1 does not properly initialize the XML parsers, which allows context-dependent malicious users to conduct XML External Entity (XXE) attacks via a crafted PDF.

Vulnerable Product Search on Vulmon Subscribe to Product

apache pdfbox 1.8.9

apache pdfbox 1.8.7

apache pdfbox 1.8.1

apache pdfbox 1.8.2

apache pdfbox 2.0

apache pdfbox 1.8.4

apache pdfbox 1.8.3

apache pdfbox 1.8.0

apache pdfbox 1.8.6

apache pdfbox 1.8.11

apache pdfbox 1.8.10

apache pdfbox 1.8.8

apache pdfbox 1.8.5

debian debian linux 8.0

Vendor Advisories

It was found that the parsing of XMP and other XML formats in PDF by Apache PDFBox would expand entity references A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks ...