ET WEB_SPECIFIC_APPS Apache Tika XML Ext... ET WEB_SPECIFIC_APPS Apache Tika XML External Entity Injection (CVE-2025-66516)
Here you can find all the details about the rule " ET WEB_SPECIFIC_APPS Apache Tika XML Ext... ET WEB_SPECIFIC_APPS Apache Tika XML External Entity Injection (CVE-2025-66516) ". Propose edits, view related rules, and engage with the community through comments.
[[ currentRule.title ]]
[[ currentRule.description ]]
Rule Content
v 1.0 v [[ currentRule.version ]][[ currentRule.to_string ]]
{
"uuid": "f8980653-761b-4906-88d1-927a3fa0657c",
"Object": [
{
"name": "suricata",
"meta-category": "network",
"template_uuid": "3c177337-fb80-405a-a6c1-1b2ddea8684a",
"description": "An object describing one or more Suricata rule(s) along with version and contextual information.",
"template_version": "2",
"uuid": "63acac86-1f49-41b6-80ed-b1b884fc37d1",
"Attribute": [
{
"uuid": "d5ea987e-b21b-4ef9-a586-cb8950c3ccc4",
"object_relation": "suricata",
"value": "alert http any any -> $HOME_NET any (msg:\"ET WEB_SPECIFIC_APPS Apache Tika XML External Entity Injection (CVE-2025-66516)\"; flow:established,to_server; http.request_body; content:\"|25|PDF|2d|1|2e|\"; content:\"|0a 2f|NeedAppearances|20|\"; fast_pattern; content:\"|0a 2f|XFA|20|\"; content:\"|3c 21|ENTITY|20|\"; distance:0; content:\"|20|SYSTEM|20|\"; distance:0; reference:url,xz.aliyun.com/news/90783; reference:cve,2025-66516; classtype:web-application-attack; sid:2066322; rev:1; metadata:affected_product Apache_Tika, attack_target Server, tls_state TLSDecrypt, created_at 2025_12_15, cve CVE_2025_66516, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, updated_at 2025_12_15, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)",
"type": "snort",
"disable_correlation": false,
"to_ids": true,
"category": "Network activity"
},
{
"uuid": "d9e3884a-7f94-419b-a20a-acd3e17c5316",
"object_relation": "suricata-rule-name",
"value": "ET WEB_SPECIFIC_APPS Apache Tika XML External Entity Injection (CVE-2025-66516)",
"type": "text",
"disable_correlation": false,
"to_ids": false,
"category": "Other"
},
{
"uuid": "450b570e-56e2-409d-93df-aee8ae1383bc",
"object_relation": "comment",
"value": "No description provided",
"type": "comment",
"disable_correlation": false,
"to_ids": false,
"category": "Other"
},
{
"uuid": "b44c6654-9bef-428a-b370-ee2b05a176a9",
"object_relation": "version",
"value": "1",
"type": "text",
"disable_correlation": false,
"to_ids": false,
"category": "Other"
},
{
"uuid": "06b6ba9f-3f69-46f3-82e0-72a189cd6b90",
"object_relation": "reference",
"value": "emerging-all.rules.zip by admin admin",
"type": "link",
"disable_correlation": false,
"to_ids": false,
"category": "External analysis"
}
],
"distribution": "5",
"sharing_group_id": "0"
}
]
}
Similar Rules
Related Bundles
[[ bundleListRule.length ]] TotalNo bundles found for this rule.
Please log in to propose an edit.
No edit proposals found for this rule.
[[ comments_list.length ]] Comments
Join the conversation
Login to replyCommunity Discussion
No comments yet
Be the first to share your thoughts on this rule!