XXE (Xml eXternal Entity) Attack, JAXB and Jersey

From: Paul Sandoz <Paul.Sandoz_at_Sun.COM>
Date: Thu, 09 Jul 2009 14:09:18 +0200


A developer on the Jersey list pointed out that when using JAXB
unmarshalling with Jersey applications are vulnerable to XXE attacks:

It is not currently clear what app server is being utilized, or if
Grizzly is being utilized.

When applications are deployed in GF are there any defaults w.r.t. to
JAXP configuration or limitations on what files may be accessed from
the application ?
