almost all XML entity attacks are prevented // Xerces 2 only - http://xerces.apache.org/xerces2 /xerces-j/features.html#external-general-entities // Xerces 2 - http://xerces.apache.org/xerces2 xerces-j/features.html#external-parameter-entities // Xerces 2 - http://xerces.apache.org/xerces2