ID:13068 - Exploit for XML External Entity injection in Apache Tika - CVE-2025-54988
Published: September 9, 2026
Apache Tika
webMethods Integration Server
Astronomer with IBM
IBM Observability with Instana
IBM i Access Client Solutions
Operations Analytics - Log Analysis
IBM SPSS Analytic Server
Atlassian Fisheye
Crucible Server
OpenPages for IBM Cloud Pak for Data
Communications Unified Assurance
Crowd Data Center
Crowd Server
Oracle Communications Order and Service Management
Confluence Server
Confluence Data Center
Enterprise Search
Elasticsearch
PeopleSoft Enterprise PeopleTools
OpenPages Cloud pak for data service version
Bamboo Server
Jira Software Server
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
FortiDLP Agent
Oracle Commerce Guided Search
IBM InfoSphere Information Server
Oracle Business Process Management Suite
Oracle Middleware Common Libraries and Tools
IBM SPSS Modeler
Ubuntu
Primavera Unifier
ColdFusion
tika (Ubuntu package)
Red Hat OpenShift Dev Spaces
Content Collector for Microsoft SharePoint
Content Collector for File Systems
Content Collector for Email
Red Hat Camel for Spring Boot
Cloudera Data Platform Private Cloud Base for IBM
IBM OpenPages with Watson
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input within the PDF parser module. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.