CVE-2017-9096
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
Improper Restriction of XML External Entity Reference in iText
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | com.itextpdf:itextpdf | <5.5.12 | 5.5.12 |
| Maven | com.itextpdf:itextpdf | >=7.0.0,<7.0.3 | 7.0.3 |
| Maven | com.lowagie:itext | <=4.2.2 | |
References
- http://www.securityfocus.com/archive/1/541483/100/0/threaded
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
- https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2017-017_itext_xml_external_entity_attack.txt
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://nvd.nist.gov/vuln/detail/CVE-2017-9096
CWEs
CWE-611
Verify integrity in audit chain (admin only). AS-IS.