SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
{ "ubuntu_priority": "medium" }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.7.1-3", "binary_name": "libsimple-xml-java" }, { "binary_version": "2.7.1-3", "binary_name": "libsimple-xml-java-doc" } ] }