> Can anyone tell me that this vulnerability also exists in xmltooling-1.4.1 jar > from java end. If yes should I upgrade this jar.. The advisory is for C++, not Java, and you're already running on EOL Java code that we no longer maintain so you have bigger problems to deal with. -- Scott