dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| dom4j_project | dom4j | 2.0.0 - 2.0.3 | - |
| dom4j_project | dom4j | 2.1.0 - 2.1.1 | - |
| debian | debian_linux | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
34
Affected Products
58
References
dom4j_project / dom4j
| - |
| oracle | flexcube_investor_servicing | - | - |
| oracle | flexcube_investor_servicing | - | - |
| oracle | flexcube_investor_servicing | - | - |
| oracle | flexcube_investor_servicing | - | - |
| oracle | flexcube_investor_servicing | - | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | 16.1.0.0 - 16.2.20.1 | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | 17.1.0.0 - 17.12.17.1 | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | 18.1.0.0 - 18.8.19.0 | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | 19.12.0.0 - 19.12.6.0 | - |
| oracle | rapid_planning | - | - |
| oracle | rapid_planning | - | - |
| oracle | retail_integration_bus | - | - |
| oracle | retail_integration_bus | - | - |
| oracle | utilities_framework | 4.3.0.2.0 - 4.3.0.6.0 | - |
| oracle | utilities_framework | - | - |
| oracle | utilities_framework | - | - |
| oracle | utilities_framework | - | - |
| oracle | utilities_framework | - | - |
| oracle | utilities_framework | - | - |
| redhat | satellite | - | - |
| redhat | satellite_capsule | - | - |
| redhat | jboss_enterprise_application_platform | - | - |
| redhat | jboss_enterprise_application_platform | - | - |
| redhat | jboss_enterprise_application_platform | - | - |
| redhat | jboss_enterprise_application_platform | - | - |
| redhat | jboss_enterprise_application_platform | - | - |
| netapp | oncommand_workflow_automation | - | - |
| netapp | snap_creator_framework | - | - |
| netapp | snapcenter | - | - |
| netapp | snapmanager | - | - |
| netapp | snapmanager | - | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability
Impact