Medium
Apache Xerces2 Java XML Parser is vulnerable to a denial of service, caused by an infinite flaw in the XML parser. By persuading a victim to open a specially-crafted XML document payloads, a remote attacker could exploit this vulnerability to consume system resources for prolonged duration, and results in a denial of service condition.
Apache
Upgrade to the latest version of Apache Xerces, available from the Apache Web site.