CVE-2020-10683

Aliases:GHSA-hwj3-m3p6-hj38
Modified
Published: 01 May 2020, 18:55
Last modified:04 Aug 2024, 11:06

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
6.96% LOW
7% probability -1.34%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 May 2020, 18:55
Published
Vulnerability first disclosed
04 Aug 2024, 11:06
Last Modified
Vulnerability information updated

Description

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 6.96% Percentile: 92%

Techniques & Countermeasures

  • CWE-611Improper Restriction of XML External Entity Reference

    The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Systems

  • canonicalubuntu_linux

    16.04

  • dom4j_projectdom4j

    < 2.0.3 | ≥ 2.1.0, < 2.1.3

  • dom4jdom4j

    ≤ 1.6.1

  • org.dom4jdom4j

    < 2.0.3 | ≥ 2.1.0, < 2.1.3

  • netapponcommand_api_services

    na

  • netapponcommand_workflow_automation

    na

  • netappsnap_creator_framework

    na

  • netappsnapcenter

    na

  • netappsnapmanager

    na

  • opensuseleap

    15.1

  • oracleagile_plm

    9.3.3 | 9.3.5

  • oracleapplication_testing_suite

    13.3.0.1

  • oraclebanking_platform

    ≥ 2.4.0, ≤ 2.10.0

  • oraclebusiness_process_management_suite

    12.2.1.3.0 | 12.2.1.4.0

  • oraclecommunications_application_session_controller

    3.9m0p1

  • oraclecommunications_diameter_signaling_router

    ≥ 8.0.0, ≤ 8.2.2

  • oraclecommunications_unified_inventory_management

    7.3.0 | 7.4.0

  • oracledata_integrator

    12.2.1.3.0 | 12.2.1.4.0

  • oracledocumaker

    ≥ 12.6.0, ≤ 12.6.4

  • oracleendeca_information_discovery_integrator

    3.2.0

  • oracleenterprise_data_quality

    11.1.1.9.0 | 12.2.1.3.0

  • oracleenterprise_manager_base_platform

    13.4.0.0

  • oraclefinancial_services_analytical_applications_infrastructure

    ≥ 8.0.6, ≤ 8.1.0

  • oracleflexcube_core_banking

    11.7.0 | 11.8.0 | 11.9.0 | 11.10.0

  • UnknownFusion Middleware

    12.2.1.4.0

  • oraclehealth_sciences_empirica_signal

    9.0

  • oraclehealth_sciences_information_manager

    3.0.1

  • oracleinsurance_policy_administration_j2ee

    ≥ 11.1.0, ≤ 11.3.0 | 10.2.0 | 10.2.4 | 11.0.2

  • oracleinsurance_rules_palette

    ≥ 11.1.0, ≤ 11.3.0 | 10.2.0 | 10.2.4 | 11.0.2

  • oraclejdeveloper

    12.2.1.4.0

  • oracleprimavera_p6_enterprise_project_portfolio_management

    ≥ 16.1.0.0, ≤ 16.2.20.1 | ≥ 17.1.0.0, ≤ 17.12.17.1 | ≥ 18.1.0.0, ≤ 18.8.19.0 | ≥ 19.12.0.0, ≤ 19.12.6.0

  • oraclerapid_planning

    12.1 | 12.2

  • oracleretail_customer_management_and_segmentation_foundation

    16.0 | 17.0 | 18.0 | 19.0

  • oracleretail_integration_bus

    15.0 | 16.0

  • oracleretail_order_broker

    15.0 | 16.0 | 18.0 | 19.0 | 19.1

  • oracleretail_price_management

    14.0.3 | 14.1.3.0 | 15.0.3.0 | 16.0.3.0

  • oracleretail_xstore_point_of_service

    15.0.4 | 16.0.6 | 17.0.4 | 18.0.3

  • oraclestoragetek_tape_analytics_sw_tool

    2.3

  • oracleutilities_framework

    ≥ 4.3.0.1.0, ≤ 4.3.0.6.0 | 2.2.0.0.0 | 4.2.0.2.0 | 4.2.0.3.0 | 4.4.0.0.0 | 4.4.0.2.0

  • oraclewebcenter_portal

    11.1.1.9.0 | 12.2.1.3.0 | 12.2.1.4.0

References (28)