High severity7.8NVD Advisory· Published Sep 30, 2017· Updated May 13, 2026
CVE-2016-4434
CVE-2016-4434
Description
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tika:tika-coreMaven | < 1.13 | 1.13 |
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- github.com/advisories/GHSA-4xr4-4c65-hj7fghsaADVISORY
- mail-archives.apache.org/mod_mbox/tika-dev/201605.mbox/%3C1705136517.1175366.1464278135251.JavaMail.yahoo%40mail.yahoo.com%3EnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-4434ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2017-0248.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2017-0249.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2017-0272.htmlnvdWEB
- www.securityfocus.com/archive/1/538500/100/0/threadednvdWEB
- lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3EghsaWEB
- lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Envd
News mentions
0No linked articles in our index yet.