The product processes an XML document that can contain XML
entities with URLs that resolve to documents outside of the intended sphere of
control, causing the product to embed incorrect documents into its
The software requires the use of XML documents and allows their
structure to be defined with a Document Type Definition (DTD). The software
allows the DTD to recursively define entities which can lead to explosive growth
of data when parsed.