Remove Apache Xerces Dependencies
Overview
Starting with brXM version 14.6.0, XML parsing has been updated to use new XML parser properties introduced in JAXP 1.5. This update improves XML parsing and security (CMS-14480).
If your project includes an older JAXP implementation on the classpath, such as Xerces, this can override the default Java XML parsers and cause compatibility issues. Xerces versions that do not support JAXP 1.5 security features may trigger errors or warnings like:
java.lang.IllegalArgumentException: Property 'http://javax.xml.XMLConstants/property/accessExternalDTD' is not recognized.
Bloomreach Content removed Xerces as a dependency in version 12.3.0 (CMS-11122). For details, see the 12.3.0 upgrade steps.
When to Use
Apply these steps if your implementation project includes Xerces dependencies or you encounter XML parser errors after upgrading to version 14.6.0 or later.
Prerequisites
- Access to your project's Maven configuration
- Ability to modify system properties for your application runtime
Steps to Remove Xerces Dependencies
-
Remove Xerces Dependencies from the Project
Eliminate all direct and transitive dependencies on the Xerces library so the JRE's built-in implementation is used. Analyze your project's dependency graph with:
mvn dependency:treeLook for JAR files such as
xercesImpl-2.9.1.jaror dependency tree entries likexerces:xercesImpl:jar:2.9.1:compile. To exclude Xerces from your dependencies, add the following exclusion to your Maven configuration:<exclusions> <exclusion> <groupId>xerces</groupId> <artifactId>xercesImpl</artifactId> </exclusion> </exclusions> -
Set the DocumentBuilderFactory System Property
Configure the system property
javax.xml.parsers.DocumentBuilderFactoryto use the internal JAXP DocumentBuilder. This implementation is provided by the JRE and works with OpenJDK (for example, AdoptOpenJDK 1.8.0_292-b10).javax.xml.parsers.DocumentBuilderFactory=com.sun.org.apache.xerces.internal.jaxp.DocumentBuilderFactoryImplFor
cargo.runconfiguration, use:<javax.xml.parsers.DocumentBuilderFactory>com.sun.org.apache.xerces.internal.jaxp.DocumentBuilderFactoryImpl</javax.xml.parsers.DocumentBuilderFactory> -
Set the TransformerFactory System Property (If Required)
Some use cases, such as projects using the Sitemap plugin, may require setting the
javax.xml.transform.TransformerFactorysystem property:javax.xml.transform.TransformerFactory=com.sun.org.apache.xalan.internal.xsltc.trax.TransformerFactoryImplFor
cargo.runconfiguration, use:<javax.xml.transform.TransformerFactory>com.sun.org.apache.xalan.internal.xsltc.trax.TransformerFactoryImpl</javax.xml.transform.TransformerFactory>
Verification
- Confirm that no Xerces JAR files are present in your deployed application.
- Ensure that XML parsing and transformation work as expected without errors related to unsupported properties.
- Check application logs for the absence of
IllegalArgumentExceptionmessages referencing XML parser properties.
Additional Resources
For details on JAXP 1.5 properties, see the JAXP Properties documentation.