← Back

CVE-2018-11761

nvd nist
Published: Sep 19, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

Affected (3)

1 product
Tika
1 product
Business Process Management Suite
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 0.1 to 1.18
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.1.3.0.0
Version 12.2.1.3.0

Timeline

No history available yet.