Description
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
Mitigation
We recommend upgrading to a version of this component that is not vulnerable to this specific issue.