# xercesImpl2.12.2

Latest

org.exist-db.thirdparty.xerces

jar

Published Mar 31, 2022 • Policy compliance

[ Maven Registry ](https://central.sonatype.com/artifact/org.exist-db.thirdparty.xerces/xercesImpl/2.12.2)

Developer Trust Score

N/A

**Recommended Version:** [x.y.z](https://guide.sonatype.com/component/maven/org.exist-db.thirdparty.xerces%3AxercesImpl/x.y.z)

Recommended upgrade that meets your policy.

[ Compare Versions ](https://guide.sonatype.com/component/maven/org.exist-db.thirdparty.xerces%3AxercesImpl/2.12.2/versions)

## Overview

### Versions
3

### Vulnerabilities
2

### Dependencies
1

---

**Severity**

Critical (1)

High (0)

Medium (0)

Low (0)

**CVSS Score**

0.0

**EPSS Score**

0.0

**Malware**

All

## KEV Status

All

Known Exploited

Not in KEV Catalog: No known exploits

Published

All

Last 7 days

Last 30 days

Last 60 days

Last 90 days

Last 6 months

Last year

Last 2 years

### Filter

Sort: Published (Newest first)

Published (Newest first)

Published (Oldest first)

CVSS Score (Critical to Low)

CVSS Score (Low to Critical)

---

### Vulnerability Details

**CVE-2017-7503**  
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.  
**Severity:** Critical  
**Published:** Jul 12, 2017

---

org.exist-db.thirdparty.xerces/xercesImpl… | Sonatype Guide
