← Back

CVE-2017-9096

nvd nist
Published: Nov 8, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

Affected (4)

Products: Itextpdf: Itext
1 product
Itext
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Itextpdf
Before 5.5.12
Version 7.0.0
Version 7.0.1
Version 7.0.2

Timeline

No history available yet.