fop: XML external entity processing vulnerability
Published Apr 18, 2017
7.5
HIGHCVSS 3.0
EPSS 2.52%
Description
In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
Affected products
-
- Version before 2.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache FOP | n/a |
|
- ≤ 2.1
No data.
Red Hat Enterprise Linux 6
fop
Will not fix
Red Hat Enterprise Linux 7
fop
Will not fix
Red Hat JBoss Fuse 6
camel
Will not fix
Red Hat JBoss Fuse Service Works 6
fop
Will not fix
Red Hat Software Collections
rh-maven33-fop
Will not fix
Red Hat Virtualization 4
fop
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | fop | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | fop | Will not fix | n/a |
| Red Hat JBoss Fuse 6 | camel | Will not fix | n/a |
| Red Hat JBoss Fuse Service Works 6 | fop | Will not fix | n/a |
| Red Hat Software Collections | rh-maven33-fop | Will not fix | n/a |
| Red Hat Virtualization 4 | fop | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The fop packager is no longer used or required by the Red Hat Virtualization Manager. Red Hat recommends removing it after upgrading to Red Hat Virtualization 4.1.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:M/Au:S/C:C/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (40 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.52% (0.02519) | 84.27th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.96% (0.02960) | 85.38th | v5 (v2026.06.15) |
| Mar 4, 2026 | 2.45% (0.02449) | 84.93th | v4 (v2025.03.14) |
| Mar 1, 2026 | 1.03% (0.01027) | 77.09th | v4 (v2025.03.14) |
| Feb 4, 2026 | 2.11% (0.02110) | 83.73th | v4 (v2025.03.14) |
| Feb 1, 2026 | 0.88% (0.00882) | 75.06th | v4 (v2025.03.14) |
| Jan 4, 2026 | 2.11% (0.02110) | 83.64th | v4 (v2025.03.14) |
| Jan 1, 2026 | 0.88% (0.00882) | 75.00th | v4 (v2025.03.14) |
| Dec 4, 2025 | 2.11% (0.02110) | 83.56th | v4 (v2025.03.14) |
| Dec 1, 2025 | 0.88% (0.00882) | 74.78th | v4 (v2025.03.14) |
| Nov 21, 2025 | 2.11% (0.02110) | 83.55th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.00% (0.01001) | 75.05th | v4 (v2025.03.14) |
| Nov 4, 2025 | 2.11% (0.02110) | 83.52th | v4 (v2025.03.14) |
| Nov 1, 2025 | 0.88% (0.00882) | 74.80th | v4 (v2025.03.14) |
| Oct 4, 2025 | 2.11% (0.02110) | 83.47th | v4 (v2025.03.14) |
| Oct 1, 2025 | 0.88% (0.00882) | 74.70th | v4 (v2025.03.14) |
| Sep 4, 2025 | 2.11% (0.02110) | 83.44th | v4 (v2025.03.14) |
| Sep 1, 2025 | 0.88% (0.00882) | 74.60th | v4 (v2025.03.14) |
| Aug 4, 2025 | 2.11% (0.02110) | 83.40th | v4 (v2025.03.14) |
| Aug 1, 2025 | 0.88% (0.00882) | 74.56th | v4 (v2025.03.14) |
| May 4, 2025 | 1.90% (0.01897) | 82.23th | v4 (v2025.03.14) |
| May 1, 2025 | 0.79% (0.00792) | 72.74th | v4 (v2025.03.14) |
| Apr 7, 2025 | 1.90% (0.01897) | 81.68th | v4 (v2025.03.14) |
| Apr 6, 2025 | 0.79% (0.00792) | 71.78th | v4 (v2025.03.14) |
| Apr 1, 2025 | 1.90% (0.01897) | 81.63th | v4 (v2025.03.14) |
| Mar 31, 2025 | 0.79% (0.00792) | 71.68th | v4 (v2025.03.14) |
| Mar 27, 2025 | 1.90% (0.01897) | 81.09th | v4 (v2025.03.14) |
| Mar 25, 2025 | 0.79% (0.00792) | 71.56th | v4 (v2025.03.14) |
| Mar 24, 2025 | 1.90% (0.01897) | 81.59th | v4 (v2025.03.14) |
| Mar 22, 2025 | 0.79% (0.00792) | 71.76th | v4 (v2025.03.14) |
| Mar 21, 2025 | 1.90% (0.01897) | 81.70th | v4 (v2025.03.14) |
| Mar 20, 2025 | 0.79% (0.00792) | 71.76th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.90% (0.01897) | 82.01th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.32% (0.00320) | 71.40th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.32% (0.00320) | 69.75th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.32% (0.00320) | 65.83th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.16% (0.01164) | 61.38th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.16% (0.01164) | 34.94th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.79% (0.03793) | 72.36th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.05% (0.03053) | 0.00th | v1 |
References (9)
- http://www.debian.org/security/2017/dsa-3864 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/97947 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2017-5661 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1443585 Issue Tracking
- https://github.com/advisories/GHSA-5hg8-r9vq-gjqp Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-5661
- https://www.cve.org/CVERecord?id=CVE-2017-5661
- https://www.tenable.com/security/tns-2021-14 x_refsource_CONFIRM
- https://xmlgraphics.apache.org/security.html x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.debian.org/security/2017/dsa-3864 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securityfocus.com/bid/97947 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2017-5661 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1443585 | Issue Tracking | |
| https://github.com/advisories/GHSA-5hg8-r9vq-gjqp | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-5661 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-5661 | ||
| https://www.tenable.com/security/tns-2021-14 | x_refsource_CONFIRM | |
| https://xmlgraphics.apache.org/security.html | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.