XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1832
Reference (s):
- BID:93132
- URL: http://www.securityfocus.com/bid/93132
- http://www-01.ibm.com/support/docview.wss?uid=swg21990100
- URL: http://www-01.ibm.com/support/docview.wss?uid=swg21990100
- https://issues.apache.org/jira/browse/DERBY-6807

