# xercesImpl2.12.1-sp1

Latest

org.codelibs.xerces

jar

Published Aug 6, 2020 • Policy compliance

[**maven Registry**](https://central.sonatype.com/artifact/org.codelibs.xerces/xercesImpl/2.12.1-sp1)

## Developer Trust Score

N/A

## Recommended Version:

[x.y.z](https://guide.sonatype.com/component/maven/org.codelibs.xerces%3AxercesImpl/x.y.z)

Recommended upgrade that meets your policy.

[**Compare Versions**](https://guide.sonatype.com/component/maven/org.codelibs.xerces%3AxercesImpl/2.12.1-sp1/versions)

## Overview
### Versions
2

### Vulnerabilities
3

### Dependencies
0

## Severity
- **Critical (1)**  
- **High (0)**  
- **Medium (0)**  
- **Low (0)**

## CVSS Score
0.0

## EPSS Score
0.0

## Malware
All

## KEV Status
All  
- Known Exploited: No known exploits

### Vulnerability Detail

[9.8 CVE-2017-7503

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

**affected**

**Severity** Critical

**Published** Jul 12, 2017](https://guide.sonatype.com/vulnerability/CVE-2017-7503)

org.codelibs.xerces/xercesImpl 2.12.1-sp1… | Sonatype Guide
