XML External Entity injection in iText - CVE-2017-9096
Published: November 8, 2017 / Updated: July 18, 2020
Vulnerability identifier: #VU31399
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9096
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.
Affected software
iText
IBM Tivoli Network Manager (ITNM)
Primavera Unifier
EMC Integrated Data Protection Appliance
Storage Resource Manager
Daeja ViewONE
Dell EMC Storage Monitoring and Reporting (SMR)
EMC Data Protection Advisor
IBM Tivoli Network Manager (ITNM)
Primavera Unifier
EMC Integrated Data Protection Appliance
Storage Resource Manager
Daeja ViewONE
Dell EMC Storage Monitoring and Reporting (SMR)
EMC Data Protection Advisor
How to mitigate CVE-2017-9096
Install update from vendor's website.
iText - update to 5.5.12
EMC Integrated Data Protection Appliance - update to 2.7.6
Storage Resource Manager - update to 5.0.2.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.2
Daeja ViewONE - update to 5.0.14 iFix 5
EMC Data Protection Advisor - update to 19.10 PB22
EMC Integrated Data Protection Appliance - update to 2.7.6
Storage Resource Manager - update to 5.0.2.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.2
Daeja ViewONE - update to 5.0.14 iFix 5
EMC Data Protection Advisor - update to 19.10 PB22
External References
Related Security Bulletins
- XML External Entity injection in iText
- Multiple vulnerabilities in Primavera Unifier
- XML external entity injection in IBM Tivoli Network Manager
- Multiple vulnerabilities in Data Protection Advisor
- XML external entity injection in Daeja ViewONE Professional, Standard & Virtual
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)