XML External Entity injection in iText - CVE-2017-9096

 

XML External Entity injection in iText - CVE-2017-9096

Published: November 8, 2017 / Updated: July 18, 2020


Vulnerability identifier: #VU31399
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9096
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.


Affected software

iText
IBM Tivoli Network Manager (ITNM)
Primavera Unifier
EMC Integrated Data Protection Appliance
Storage Resource Manager
Daeja ViewONE
Dell EMC Storage Monitoring and Reporting (SMR)
EMC Data Protection Advisor

How to mitigate CVE-2017-9096

Install update from vendor's website.

iText - update to 5.5.12
EMC Integrated Data Protection Appliance - update to 2.7.6
Storage Resource Manager - update to 5.0.2.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.2
Daeja ViewONE - update to 5.0.14 iFix 5
EMC Data Protection Advisor - update to 19.10 PB22

External References

Related Security Bulletins