High severity7.8NVD Advisory· Published Sep 30, 2017· Updated Jun 17, 2026
CVE-2016-4434
CVE-2016-4434
Description
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tika:tika-coreMaven | < 1.13 | 1.13 |
Affected products
2Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-4xr4-4c65-hj7fghsaADVISORY
- mail-archives.apache.org/mod_mbox/tika-dev/201605.mbox/%3C1705136517.1175366.1464278135251.JavaMail.yahoo%40mail.yahoo.com%3EnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-4434ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2017-0248.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2017-0249.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2017-0272.htmlnvdWEB
- www.securityfocus.com/archive/1/538500/100/0/threadednvdWEB
- lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3EghsaWEB
- lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Envd
News mentions
0No linked articles in our index yet.