My Oracle Support Banner

XML External Entity (XXE) Injection Concern with Oracle Commerce REST Web Services (Doc ID 2616098.1)

Last updated on DECEMBER 04, 2019

Applies to:

Oracle Commerce Platform - Version 11.1 and later
Information in this document applies to any platform.
Reported Version: 11.1

Goal

XML external entity (XXE) injection concern with addItemToOrder rest service in CartModifierActor.  Its content-type can be application/xml and SOAP XML request can be sent to the URL and the underlying parser is able to parse the xml request.  This concern is not specific to addItemToOrder but other rest services.  Is there way to block or avoid or error out XML request?

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Goal
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.