CVE-2015-1833: Apache Jackrabbit
Medium severity, CVSS 6.4. EPSS: 55.9% chance of exploitation in the next 30 days.
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.
Affected products
- Apache Jackrabbit: up to and including 2.0.5; version 2.2.0 only; version 2.2.1 only; version 2.2.2 only; version 2.2.4 only; version 2.2.5 only; …
Published 2015-05-29. Last modified 2026-06-17.