CVE-2016-4216 is an XML External Entity (XXE) vulnerability in XMPCore within Adobe XMP Toolkit for Java versions prior to 5.1.3, allowing remote attackers to read arbitrary files. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, potentially leading to significant information disclosure. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1.2CPE matchmatch criteria | cpe:2.3:a:adobe:xmp_toolkit:*:*:*:*:*:java:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.