# org.apache.xerces2.9.0

## Overview

### Versions: 1
### Vulnerabilities: 5
### Dependencies: 0

### Recommended Version
Recommended Version: [x.y.z](https://guide.sonatype.com/component/maven/org.eclipse.birt.runtime.3_7_1%3Aorg.apache.xerces/x.y.z)

### Developer Trust Score
N/A

## Vulnerability Details

### CVE-2017-7503

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

**Severity:** Critical  
**Published:** Jul 12, 2017

### Severity breakdown
- Critical (1)
- High (0)
- Medium (0)
- Low (0)

### CVSS Score
0.01

### EPSS Score
0.01

### Malware Status
All
