XML External Entity injection in Apache Tika - CVE-2025-66516,CVE-2025-54988
Published: August 22, 2025 / Updated: January 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input within the PDF parser module. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
IBM Observability with Instana
IBM SPSS Analytic Server
Crucible Server
Crowd Data Center
Confluence Data Center
Bamboo Server
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
Oracle Middleware Common Libraries and Tools
IBM SPSS Modeler
Red Hat OpenShift Dev Spaces
Content Collector for Microsoft SharePoint
Content Collector for File Systems
Content Collector for Email
webMethods Integration Server
Astronomer with IBM
Operations Analytics - Log Analysis
OpenPages for IBM Cloud Pak for Data
OpenPages Cloud pak for data service version
IBM OpenPages with Watson
IBM i Access Client Solutions
Primavera Unifier
Atlassian Fisheye
PeopleSoft Enterprise PeopleTools
Communications Unified Assurance
Crowd Server
Oracle Communications Order and Service Management
Confluence Server
Enterprise Search
IBM InfoSphere Information Server
Elasticsearch
Oracle Business Process Management Suite
Cloudera Data Platform Private Cloud Base for IBM
Jira Software Server
FortiDLP Agent
Oracle Commerce Guided Search
Ubuntu
ColdFusion
tika (Ubuntu package)
Red Hat Camel for Spring Boot
How to mitigate CVE-2025-66516,CVE-2025-54988
webMethods Integration Server - update to IS 11.1 Core Fix9
Astronomer with IBM - update to 1.1.0
IBM Observability with Instana - update to 1.0.307
Operations Analytics - Log Analysis - update to 1.3.8.4
Atlassian Fisheye - update to 4.9.6
Crucible Server - update to 4.9.6
OpenPages for IBM Cloud Pak for Data - update to 5.2.2
Crowd Data Center - addressed in versions 6.3.4, 7.1.2
Crowd Server - addressed in versions 6.3.4, 7.1.2
Confluence Server - addressed in versions 8.5.31, 9.2.13, 10.2.2
Confluence Data Center - addressed in versions 8.5.31, 9.2.13, 10.2.2
Enterprise Search - addressed in versions 8.18.6, 8.19.3
Elasticsearch - addressed in versions 8.18.6, 8.19.3, 9.0.6, 9.1.3
OpenPages Cloud pak for data service version - update to 9.5.2
Bamboo Server - addressed in versions 9.6.20, 10.2.12, 12.0.2
Jira Software Server - addressed in versions 9.12.30, 10.3.13, 11.2.0
Jira Software Data Center - addressed in versions 9.12.30, 10.3.13, 11.2.0
Jira Service Management Server - addressed in versions 10.3.15, 11.2.1
Jira Service Management Data Center - addressed in versions 10.3.15, 11.2.1
FortiDLP Agent - update to 12.2.3
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
ColdFusion - addressed in versions 2023 Update 18, 2025 Update 6
tika (Ubuntu package) - addressed in versions 1.22-1ubuntu0.1~esm2, 1.22-2+deb11u1build0.22.04.1
Red Hat OpenShift Dev Spaces - update to 3.25.0
Content Collector for Microsoft SharePoint - update to 4.0.1.17 Fix Pack 17
Content Collector for File Systems - update to 4.0.1.17 Fix Pack 17
Content Collector for Email - update to 4.0.1.17 Fix Pack 17
Red Hat Camel for Spring Boot - update to 4.14.2
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.9 SP1 CHF 14, 7.3.1.700 SP3 CHF 2
IBM OpenPages with Watson - addressed in versions 8.3.0.3.3, 9.0.0.5.7, 9.1.2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- XXE in Apache Tika
- Elasticsearch update for Apache Tika
- Elastic Enterprise Search update for Apache Tika
- FortiDLP agent update for Apache Tika
- IBM OpenPages update for Apache Tika
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4.14
- Jira Software Data Center and Server update for Apache Tika
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Jira Service Management Data Center and Server update for Apache Tika
- Atlassian Crucible and Fisheye update for Apache Tika
- Bamboo Data Center and Server update for Apache Tika
- Crowd Data Center and Server update for Apache Tika
- Confluence Data Center and Server update for Apache Tika
- Adobe ColdFusion update for XXE in Apache Tika
- IBM i Access Family update for Apache Tika
- Multiple vulnerabilities in Primavera Unifier
- Multiple vulnerabilities in Communications Unified Assurance
- XML External Entity injection in Oracle Communications Order and Service Management
- Multiple vulnerabilities in Oracle Middleware Common Libraries and Tools
- Multiple vulnerabilities in Oracle Business Process Management Suite
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Astronomer with IBM update for Apache Tika
- IBM SPSS Analytic Server update for Apache Tika
- IBM InfoSphere Information Server update for Apache Tika
- IBM webMethods Integration update for Apache Tika tika-core
- IBM OpenPages for Cloud Pak for Data update for Apache Tika
- Crowd Data Center and Server update for tika-parsers
- Multiple vulnerabilities in IBM Observability with Instana
- Cloudera Data Platform Private Cloud Base with IBM (CDP) update for Apache Tika tika-core
- IBM Operations Analytics - Log Analysis update for Apache Tika
- IBM SPSS Modeler update for Apache Tika Core and Parsers
- Ubuntu update for tika
- IBM Content Collector for Email, File Systems, and Microsoft SharePoint update for Apache Tika