← Back

CVE-2020-10683

nvd nist
Published: May 1, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

Affected (79)

Products: Dom4j Project: Dom4j · Oracle: Agile Plm, Application Testing Suite, Banking Platform, Business Process Management Suite, Communications Application Session Controller, Communications Diameter Signaling Router, Communications Unified Inventory Management, Data Integrator, Documaker, Endeca Information Discovery Integrator, Enterprise Data Quality, Enterprise Manager Base Platform, Financial Services Analytical Applications Infrastructure, Flexcube Core Banking, Fusion Middleware, Health Sciences Empirica Signal, Health Sciences Information Manager, Insurance Policy Administration J2ee, Insurance Rules Palette, Jdeveloper, Primavera P6 Enterprise Project Portfolio Management, Rapid Planning, Retail Customer Management And Segmentation Foundation, Retail Integration Bus, Retail Order Broker, Retail Price Management, Retail Xstore Point Of Service, Storagetek Tape Analytics Sw Tool, Utilities Framework, Webcenter Portal · Opensuse: Leap · +2 more
Show all products
1 product
Dom4j
30 products
Agile Plm
Application Testing Suite
Banking Platform
Business Process Management Suite
Data Integrator
Documaker
Enterprise Data Quality
Enterprise Manager Base Platform
Flexcube Core Banking
Fusion Middleware
Health Sciences Empirica Signal
Insurance Rules Palette
Jdeveloper
Rapid Planning
Retail Integration Bus
Retail Order Broker
Retail Price Management
Retail Xstore Point Of Service
Storagetek Tape Analytics Sw Tool
Utilities Framework
Webcenter Portal
1 product
Leap
5 products
Oncommand Api Services
Oncommand Workflow Automation
Snap Creator Framework
Snapcenter
Snapmanager
1 product
Ubuntu Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Dom4j Project
Before 2.0.3
From 2.1.0 to 2.1.3
Configuration B
69 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 9.3.3
Version 9.3.5
Version 13.3.0.1
From 2.4.0 to 2.10.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 3.9m0p1
From 8.0.0 to 8.2.2
Oracle
Version 7.3.0
Version 7.4.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
From 12.6.0 to 12.6.4
Version 3.2.0
Oracle
Version 11.1.1.9.0
Version 12.2.1.3.0
Version 13.4.0.0
From 8.0.6 to 8.1.0
Oracle
Version 11.10.0
Version 11.7.0
Version 11.8.0
Version 11.9.0
Version 12.2.1.4.0
Version 9.0
Version 3.0.1
Oracle
From 11.1.0 to 11.3.0
Version 10.2.0
Version 10.2.4
Version 11.0.2
Oracle
From 11.1.0 to 11.3.0
Version 10.2.0
Version 10.2.4
Version 11.0.2
Version 12.2.1.4.0
Oracle
From 16.1.0.0 to 16.2.20.1
From 17.1.0.0 to 17.12.17.1
From 18.1.0.0 to 18.8.19.0
From 19.12.0.0 to 19.12.6.0
Oracle
Version 12.1
Version 12.2
Oracle
Version 16.0
Version 17.0
Version 18.0
Version 19.0
Oracle
Version 15.0
Version 16.0
Oracle
Version 15.0
Version 16.0
Version 18.0
Version 19.0
Version 19.1
Oracle
Version 14.0.3
Version 14.1.3.0
Version 15.0.3.0
Version 16.0.3.0
Oracle
Version 15.0.4
Version 16.0.6
Version 17.0.4
Version 18.0.3
Version 2.3
Oracle
From 4.3.0.1.0 to 4.3.0.6.0
Version 2.2.0.0.0
Version 4.2.0.2.0
Version 4.2.0.3.0
Version 4.4.0.0.0
Version 4.4.0.2.0
Oracle
Version 11.1.1.9.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration D
6 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
Netapp
All versions
All versions
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 16.04

References (40)

Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Release NotesThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.