CVE-2015-1832: Improper Restriction of XML External Entity Reference
(updated )
XML external entity (XXE) vulnerability in the SqlXmlUtil
code in Apache Derby, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI
and the XML datatype.
References
Detect and mitigate CVE-2015-1832 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →