CVE-2020-10683
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Affected (79)
Products: Dom4j Project: Dom4j · Oracle: Agile Plm, Application Testing Suite, Banking Platform, Business Process Management Suite, Communications Application Session Controller, Communications Diameter Signaling Router, Communications Unified Inventory Management, Data Integrator, Documaker, Endeca Information Discovery Integrator, Enterprise Data Quality, Enterprise Manager Base Platform, Financial Services Analytical Applications Infrastructure, Flexcube Core Banking, Fusion Middleware, Health Sciences Empirica Signal, Health Sciences Information Manager, Insurance Policy Administration J2ee, Insurance Rules Palette, Jdeveloper, Primavera P6 Enterprise Project Portfolio Management, Rapid Planning, Retail Customer Management And Segmentation Foundation, Retail Integration Bus, Retail Order Broker, Retail Price Management, Retail Xstore Point Of Service, Storagetek Tape Analytics Sw Tool, Utilities Framework, Webcenter Portal · Opensuse: Leap · +2 more
Show all products
Dom4j Project: Dom4j · Oracle: Agile Plm, Application Testing Suite, Banking Platform, Business Process Management Suite, Communications Application Session Controller, Communications Diameter Signaling Router, Communications Unified Inventory Management, Data Integrator, Documaker, Endeca Information Discovery Integrator, Enterprise Data Quality, Enterprise Manager Base Platform, Financial Services Analytical Applications Infrastructure, Flexcube Core Banking, Fusion Middleware, Health Sciences Empirica Signal, Health Sciences Information Manager, Insurance Policy Administration J2ee, Insurance Rules Palette, Jdeveloper, Primavera P6 Enterprise Project Portfolio Management, Rapid Planning, Retail Customer Management And Segmentation Foundation, Retail Integration Bus, Retail Order Broker, Retail Price Management, Retail Xstore Point Of Service, Storagetek Tape Analytics Sw Tool, Utilities Framework, Webcenter Portal · Opensuse: Leap · Netapp: Oncommand Api Services, Oncommand Workflow Automation, Snap Creator Framework, Snapcenter, Snapmanager · Canonical: Ubuntu Linux
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.3.3 | |
| Version 13.3.0.1 | |
| From 2.4.0 to 2.10.0 | |
| Version 12.2.1.3.0 | |
| Version 3.9m0p1 | |
| From 8.0.0 to 8.2.2 | |
| Version 7.3.0 | |
| Version 12.2.1.3.0 | |
| From 12.6.0 to 12.6.4 | |
| Version 3.2.0 | |
| Version 11.1.1.9.0 | |
| Version 13.4.0.0 | |
| From 8.0.6 to 8.1.0 | |
| Version 11.10.0 | |
| Version 12.2.1.4.0 | |
| Version 9.0 | |
| Version 3.0.1 | |
| From 11.1.0 to 11.3.0 | |
| From 11.1.0 to 11.3.0 | |
| Version 12.2.1.4.0 | |
| From 16.1.0.0 to 16.2.20.1 | |
| Version 12.1 | |
| Version 16.0 | |
| Version 15.0 | |
| Version 15.0 | |
| Version 14.0.3 | |
| Version 15.0.4 | |
| Version 2.3 | |
| From 4.3.0.1.0 to 4.3.0.6.0 | |
| Version 11.1.1.9.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.04 |
References (40)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Release NotesThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.