LPS-67683 XXE vulnerability in PDFBox

Description

In Liferay Portal 7.0.1 and earlier, PDFBox does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

Severity

Severity 1

Fixed Version(s)

Publication date: Tue, 23 Aug 2016 07:33:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.