# xercesImpl2.12.2

## Overview

- **Published**: Jan 27, 2022  
- **Policy Compliance**: N/A  
- **Developer Trust Score**: N/A  
- **Recommended Version**: [x.y.z](https://guide.sonatype.com/component/maven/xerces%3AxercesImpl/x.y.z)  
- **Compare Versions**: [Compare](https://guide.sonatype.com/component/maven/xerces%3AxercesImpl/2.12.2/versions)

## Versions

- **Total Versions**: 20

## Vulnerabilities

- **Total Vulnerabilities**: 2
- **Severity**: Critical (1), High (0), Medium (0), Low (0)

## CVSS Score

- **CVSS Score**: 0.0  
- **EPSS Score**: 0.0

## Malware

- **KEV Status**: Not in KEV Catalog: No known exploits

### Vulnerability Details

- **CVE-2017-7503**  
  It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.  
  - **Affected**: xerces/xercesImpl 2.12.2  
  - **Severity**: Critical  
  - **Published**: Jul 12, 2017
