CVE-2008-0628

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
06/02/2008
Last modified:
09/04/2025

Description

The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sun:jdk:1.6:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:*:update3:*:*:*:*:*:* 1.6.0 (including)


References to Advisories, Solutions, and Tools