i am using below request to send data to class
<!DOCTYPE foo [
<!ENTITY xeebri2n3 "o16ja">]>
<SubmitPaymentRequest xmlns="http://www.qwest.com/XMLSchema" xmlns:bim="http://www.qwest.com/XMLSchema/BIM">
<EPWFHeaderInfo>
<bim:RequestId>IR1BCSRDQBSIRW7745 &xeebri2n3;&xeebri2n3;&xeebri2n3;</bim:RequestId>
<bim:SendTimeStamp>2019-12-23T14:23:01.183-05:00</bim:SendTimeStamp>
<bim:MessageSrcSystem>IPS</bim:MessageSrcSystem>
</EPWFHeaderInfo>
</SubmitPaymentRequest >
i am passing xml request to below code in string format now i want that all DOCTYPE and its ENTITY will not be used before converting to java object and i am using below code to achieve that one but not able to solve the problem entity value is still appended in data field , so attacker can still attack on code so is there any way i can remove doctype and entity without throwing an exception and processed my data without any DOCTYPE
class Parsing {
public static String formatXML(String s) {
StringReader sr = null;
StringWriter sw = null;
Writer writer = null;
try {
t
XMLReader reader = XMLReaderFactory.createXMLReader();
//reader.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
reader.setFeature("http://apache.org/xml/features/nonvalidating/load-external-dtd", false);
reader.setFeature("http://xml.org/sax/features/external-general-entities", false);
reader.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
Source xmlInput = new SAXSource(reader, new InputSource(new StringReader( s )));
// sr = new StringReader(s);
//Source xmlInput = new StreamSource(sr);
sw = new StringWriter();
StreamResult xmlOutput = new StreamResult(sw);
// Configure transformer
Transformer transformer =
TransformerFactory.newInstance().newTransformer(); // An
// identity
// transformer
transformer.setOutputProperty(OutputKeys.DOCTYPE_SYSTEM,
"testing.dtd");
transformer.setOutputProperty(OutputKeys.INDENT, "yes");
transformer.setOutputProperty("{http://xml.apache.org/xslt}indent-amount",
"4");
transformer.transform(xmlInput, xmlOutput);
writer = xmlOutput.getWriter();
return writer.toString();
} catch (Exception e) {
logger.error("Caught exception", e);
}
finally{
StringBuilder errMsg = new StringBuilder("Exception caught while closing");
try{ if(sr != null) sr.close();}catch(Exception ie){logger.error(errMsg.append("StringReader").toString(),ie);}
try{ if(sw != null)sw.close();}catch(IOException ie){logger.error(errMsg.append(" StringWriter").toString(),ie);}
try{if(writer != null)writer.close();}catch(IOException ex){logger.error(errMsg.append("Writer"),ex);};
}
return s;
}
}