Remove Apache Xerces Dependencies

Overview

Starting with brXM version 14.6.0, XML parsing has been updated to use new XML parser properties introduced in JAXP 1.5. This update improves XML parsing and security (CMS-14480).

If your project includes an older JAXP implementation on the classpath, such as Xerces, this can override the default Java XML parsers and cause compatibility issues. Xerces versions that do not support JAXP 1.5 security features may trigger errors or warnings like:

java.lang.IllegalArgumentException: Property 'http://javax.xml.XMLConstants/property/accessExternalDTD' is not recognized. 

Bloomreach Content removed Xerces as a dependency in version 12.3.0 (CMS-11122). For details, see the 12.3.0 upgrade steps.

When to Use

Apply these steps if your implementation project includes Xerces dependencies or you encounter XML parser errors after upgrading to version 14.6.0 or later.

Prerequisites

  • Access to your project's Maven configuration
  • Ability to modify system properties for your application runtime

Steps to Remove Xerces Dependencies

  1. Remove Xerces Dependencies from the Project

    Eliminate all direct and transitive dependencies on the Xerces library so the JRE's built-in implementation is used. Analyze your project's dependency graph with:

    mvn dependency:tree
    

    Look for JAR files such as xercesImpl-2.9.1.jar or dependency tree entries like xerces:xercesImpl:jar:2.9.1:compile. To exclude Xerces from your dependencies, add the following exclusion to your Maven configuration:

    <exclusions> <exclusion> <groupId>xerces</groupId> <artifactId>xercesImpl</artifactId> </exclusion> </exclusions>
  2. Set the DocumentBuilderFactory System Property

    Configure the system property javax.xml.parsers.DocumentBuilderFactory to use the internal JAXP DocumentBuilder. This implementation is provided by the JRE and works with OpenJDK (for example, AdoptOpenJDK 1.8.0_292-b10).

    javax.xml.parsers.DocumentBuilderFactory=com.sun.org.apache.xerces.internal.jaxp.DocumentBuilderFactoryImpl
    

    For cargo.run configuration, use:

    <javax.xml.parsers.DocumentBuilderFactory>com.sun.org.apache.xerces.internal.jaxp.DocumentBuilderFactoryImpl</javax.xml.parsers.DocumentBuilderFactory>
  3. Set the TransformerFactory System Property (If Required)

    Some use cases, such as projects using the Sitemap plugin, may require setting the javax.xml.transform.TransformerFactory system property:

    javax.xml.transform.TransformerFactory=com.sun.org.apache.xalan.internal.xsltc.trax.TransformerFactoryImpl
    

    For cargo.run configuration, use:

    <javax.xml.transform.TransformerFactory>com.sun.org.apache.xalan.internal.xsltc.trax.TransformerFactoryImpl</javax.xml.transform.TransformerFactory>

Verification

  • Confirm that no Xerces JAR files are present in your deployed application.
  • Ensure that XML parsing and transformation work as expected without errors related to unsupported properties.
  • Check application logs for the absence of IllegalArgumentException messages referencing XML parser properties.

Additional Resources

For details on JAXP 1.5 properties, see the JAXP Properties documentation.

Share Feedback
Page: /about/upgrade-guides/minor-version-upgrades/v14/upgrade-14-5-to-14-6/remove-apache-xerces
Section: About
Category *