When Axis2 receives a message with a DOCTYPE declaration referencing a DTD (using a system ID), it will attempt to load that DTD. Since SOAP doesn't allow DTDs, we should not try to load it.
Note that the described behavior depends on the StAX parser implementation. For more information, see
WSCOMMONS-394 (which also describes a potential solution for the present issue).
|Status||Open [ 1 ]||Resolved [ 5 ]|
|Fix Version/s||1.6 [ 12313622 ]|
|Fix Version/s||1.5.2 [ 12315174 ]|
|Resolution||Fixed [ 1 ]|
|Field||Original Value||New Value|
|Summary||Message builders for SOAP and XML should not attempt to load DTDs||CVE-2010-1632: Message builders for SOAP and XML should not attempt to load DTDs|
|Priority||Minor [ 4 ]||Major [ 3 ]|