📦

jackson-dataformat-xml

Vendor: fasterxml

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 21 Total Indexed
Avg. EPSS 2.57% Exploit Prob.
Latest CVE CVE-2016-7051 Apr 14

Security Vulnerability Index

Page 1 / 3
8.6 CVSS
CVE-2016-7051
Exploit Found

XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.

EPSS: 2.36%
9.8 CVSS

XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.

EPSS: 2.78%