CVE-2016-4434
Last modified
CVE-2016-4434 is a vulnerability of currently unknown severity. Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.. EPSS estimates a 3.45% chance of exploitation in the next 30 days.
Description
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tika | 1.12 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-4434?
How severe is CVE-2016-4434?
How do I fix CVE-2016-4434?
Are you affected by CVE-2016-4434?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
