Apache Derby could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML datatype and XmlVTI. An attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service. Upstream bug: https://issues.apache.org/jira/browse/DERBY-6807 Upstream patch: https://svn.apache.org/viewvc?view=revision&revision=1691461
Created derby tracking bugs for this issue: Affects: fedora-all [bug 1381475]