Loading
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Use CWE-200, Redhat vendor hub and Jboss Middleware product page to widen CVE-2016-3674 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-4853, CVE-2017-7957 and CVE-2018-1304 for nearby disclosures in the same product family.