PatchSiren cyber security CVE debrief
CVE-2017-6055 Eparaksts CVE debrief
CVE-2017-6055 describes an XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13. According to the CVE description, a crafted .edoc file could let an attacker read arbitrary files and possibly cause other unspecified impact. NVD rates the issue as high severity (CVSS 3.0: 7.8) and maps it to CWE-611.
- Vendor
- Eparaksts
- Product
- Eparakstitajs 3
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-17
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-17
- Advisory updated
- 2026-05-13
Who should care
Organizations using eParakstitajs 3 or eParaksts Java lib, especially any deployment that accepts or processes .edoc files, should treat this as a priority update issue.
Technical summary
The weakness is an XXE condition (CWE-611) in XML handling. The affected versions listed in the CVE are eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13. The reported effect is exposure of arbitrary files, with possible additional unspecified impact. NVD’s CVSS vector is CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
Defensive priority
High. The combination of file disclosure potential, high CVSS score, and a direct version fix threshold makes this a strong patch-and-verify item for any affected installation.
Recommended defensive actions
- Upgrade eParakstitajs 3 to version 1.3.9 or later.
- Upgrade eParaksts Java lib to version 2.5.13 or later.
- Review any workflow that imports or processes .edoc files and confirm it cannot accept untrusted content without XML external entity protections.
- Validate that XML parsers used by dependent components have external entity resolution disabled where appropriate.
- Check deployment inventories for the affected product names and version ranges before and after remediation.
Evidence notes
Supported by the CVE description and NVD metadata in the supplied corpus. The CVE description states XXE exposure via crafted edoc files and the affected version ceilings. NVD provides CWE-611, the CVSS 3.0 vector, and the vulnerable CPE range for eparakstitajs_3 through 1.3.8. Vendor and third-party references are listed in the NVD record, but no additional claims are made here beyond the supplied source text.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6055 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6055
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6055 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6055
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://cert.lv/lv/2017/02/iznakusas-nedelas-zinas-par-drosibas-incidentiem-nr-4-2017
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.eparaksts.lv/en/Assistance/downloads/eparakstitajs-3-0/previous-versions-of-eparakstitajs-3-0/
[email protected] - Release Notes, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.