Document Builder Factory class − void set Ignoring Element Content Whitespace(boolean whitespace) This method specifies that the parsers created by this factory must eliminate whitespace in element content (sometimes known loosely as 'ignorable whitespace') when parsing XML documents.XML e Xternal Entity injection (XXE) is a type of attack against an application that parses XML input.

Employee; public class XMLParser SAX Employee:: ID=1 Name=Pankaj Age=29 Gender=Male Role=Java Developer Employee:: ID=2 Name=Lisa Age=35 Gender=Female Role=CEO Employee:: ID=3 Name=Tom Age=40 Gender=Male Role=Manager Employee:: ID=4 Name=Meghna Age=25 Gender=Female Role=Manager instance.

Document Builder Factory class defines a factory API that enables applications to obtain a parser that produces DOM object trees from XML documents.

The safest way to prevent XXE is always to disable DTDs (External Entities) completely.

Depending on the parser, the method should be similar to the following: Disabling DTDs also makes the parser secure against denial of services (DOS) attacks such as Billion Laughs.

