CVE-2016-4434 PUBLISHED

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.

EPSS 0.41% · 61.4th percentile

Risk Scores

EPSS Score
0.41%
61.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTStika0, 1.5-5
Ubuntu:16.04:LTStika1.5-3, 0, 1.5-4ubuntu0.1

Timeline

References

Open in Interactive Console →