GHSA-p99p-726h-c8v5 · Severity: high · Ecosystem: maven — Apache juddi-client vulnerable to XML External Entity (XXE)
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5.
Conclusion & alert: CVE-2018-1307 is rated Moderate Risk (59/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.70%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.12% | 1.70% | +0.59% |
| 2 | 2025-08-26 | 1.18% | 1.12% | -0.06% |
| 3 | 2025-03-30 | — | 1.18% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.0 | HIGH |
|
2.2 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
GHSA-p99p-726h-c8v5 · Severity: high · Ecosystem: maven — Apache juddi-client vulnerable to XML External Entity (XXE)
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2018-1307 |
| URL | Tags |
|---|---|
| http://juddi.apache.org/security.html | Vendor Advisory |
| https://issues.apache.org/jira/browse/JUDDI-987 | Issue Tracking Patch Vendor Advisory |