Fixed
Details
Assignee
Scott CantorScott CantorReporter
Unidentified Legacy AccountUnidentified Legacy AccountComponents
Details
Details
Assignee
Scott Cantor
Scott CantorReporter
Unidentified Legacy Account
Unidentified Legacy AccountComponents
Created January 10, 2018 at 2:35 PM
Updated June 24, 2021 at 1:25 PM
Resolved January 12, 2018 at 2:29 PM
An outside tester identified a specific vulnerability using a DTD internal subset that can be used in cases where the Xerces parser is too old to allow the SP to turn off DTD support. This is primarily Red Hat 7 and OpenSUSE 13 among the platforms we package.