CVE Vulnerabilities

CVE-2008-0628

Published: Feb 06, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:M/Au:N/C:N/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the external general entities property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.

Affected Software

NameVendorStart VersionEnd Version
JdkSun1.6 (including)1.6 (including)
JreSun*1.6.0 (including)
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-bea-1:1.6.0.03-1jpp.2.el5*
Sun-java6Ubuntudevel*
Sun-java6Ubuntufeisty*
Sun-java6Ubuntugutsy*
Sun-java6Ubuntuhardy*
Sun-java6Ubuntuintrepid*
Sun-java6Ubuntuupstream*

References