# Vulnerability Apache Tika 1.13 \< 3.2.2 XXE (CVE-2025-66516) and Apache Log4j 2.0-beta9 \< 2.25.3 MitM in VA scan report of server

**URL:** <https://discuss.elastic.co/t/vulnerability-apache-tika-1-13-3-2-2-xxe-cve-2025-66516-and-apache-log4j-2-0-beta9-2-25-3-mitm-in-va-scan-report-of-server/384881>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 3, 2026, 11:51am UTC](https://discuss.elastic.co/t/vulnerability-apache-tika-1-13-3-2-2-xxe-cve-2025-66516-and-apache-log4j-2-0-beta9-2-25-3-mitm-in-va-scan-report-of-server/384881 "2026-02-03T11:51:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ravinder07Sharma](https://avatars.discourse-cdn.com/v4/letter/r/f08c70/32.png) [@Ravinder07Sharma](https://discuss.elastic.co/u/Ravinder07Sharma)\
**Post date:** [February 3, 2026, 11:51am UTC](https://discuss.elastic.co/t/vulnerability-apache-tika-1-13-3-2-2-xxe-cve-2025-66516-and-apache-log4j-2-0-beta9-2-25-3-mitm-in-va-scan-report-of-server/384881/1 "2026-02-03T11:51:47Z")

</div>

we are running Elasticsearch-8.17.10 on 6 RHEL 8 servers. But we are getting vulnerability Apache Tika 1.13 \< 3.2.2 XXE (CVE-2025-66516) and Apache Log4j 2.0-beta9 \< 2.25.3 MitM in VA scan report of server. log4j vulnerability is not getting fixed by upgrading elasticsearch to version 8.19.10.How to fix these vulnerabilities?

---

<div class="post-metadata">

**Author:** ![Nguy\_n\_Trung\_Nguyen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nguy_n_trung_nguyen/32/146850_2.png) [@Nguy\_n\_Trung\_Nguyen](https://discuss.elastic.co/u/Nguy_n_Trung_Nguyen)\
**Post date:** [February 9, 2026, 10:09am UTC](https://discuss.elastic.co/t/vulnerability-apache-tika-1-13-3-2-2-xxe-cve-2025-66516-and-apache-log4j-2-0-beta9-2-25-3-mitm-in-va-scan-report-of-server/384881/2 "2026-02-09T10:09:04Z")

</div>

Hello, I’m also facing the same issue as you. I’ve upgraded to version **8.19.11** , but the security vulnerability is still present. Have you managed to resolve this problem yet? If so, please share how you fixed it with me.
