Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-28890

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2022-28890
  • Apache » Jena » Version: 4.4.0
    cpe:2.3:a:apache:jena:4.4.0


Contact Us

Shodan ® - All rights reserved