9.8

CVE-2020-10683

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dom4j Project ≫ Dom4j Version < 2.0.3
Dom4j Project ≫ Dom4j Version >= 2.1.0 < 2.1.3
Oracle ≫ Application Testing Suite Version 13.3.0.1
Oracle ≫ Banking Platform Version >= 2.4.0 <= 2.10.0
Oracle ≫ Business Process Management Suite Version 12.2.1.3.0
Oracle ≫ Business Process Management Suite Version 12.2.1.4.0
Oracle ≫ Communications Diameter Signaling Router Version >= 8.0.0 <= 8.2.2
Oracle ≫ Data Integrator Version 12.2.1.3.0
Oracle ≫ Data Integrator Version 12.2.1.4.0
Oracle ≫ Documaker Version >= 12.6.0 <= 12.6.4
Oracle ≫ Enterprise Data Quality Version 11.1.1.9.0
Oracle ≫ Enterprise Data Quality Version 12.2.1.3.0
Oracle ≫ Flexcube Core Banking Version 11.7.0
Oracle ≫ Flexcube Core Banking Version 11.8.0
Oracle ≫ Flexcube Core Banking Version 11.9.0
Oracle ≫ Flexcube Core Banking Version 11.10.0
Oracle ≫ Fusion Middleware Version 12.2.1.4.0
Oracle ≫ Insurance Policy Administration J2ee Version >= 11.1.0 <= 11.3.0
Oracle ≫ Insurance Rules Palette Version >= 11.1.0 <= 11.3.0
Oracle ≫ Insurance Rules Palette Version 10.2.0
Oracle ≫ Insurance Rules Palette Version 10.2.4
Oracle ≫ Insurance Rules Palette Version 11.0.2
Oracle ≫ Jdeveloper Version 12.2.1.4.0
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 16.1.0.0 <= 16.2.20.1
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 17.1.0.0 <= 17.12.17.1
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 18.1.0.0 <= 18.8.19.0
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 19.12.0.0 <= 19.12.6.0
Oracle ≫ Rapid Planning Version 12.1
Oracle ≫ Rapid Planning Version 12.2
Oracle ≫ Retail Integration Bus Version 15.0
Oracle ≫ Retail Integration Bus Version 16.0
Oracle ≫ Retail Order Broker Version 15.0
Oracle ≫ Retail Order Broker Version 16.0
Oracle ≫ Retail Order Broker Version 18.0
Oracle ≫ Retail Order Broker Version 19.0
Oracle ≫ Retail Order Broker Version 19.1
Oracle ≫ Retail Price Management Version 14.0.3
Oracle ≫ Retail Price Management Version 14.1.3.0
Oracle ≫ Retail Price Management Version 15.0.3.0
Oracle ≫ Retail Price Management Version 16.0.3.0
Oracle ≫ Utilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
Oracle ≫ Utilities Framework Version 2.2.0.0.0
Oracle ≫ Utilities Framework Version 4.2.0.2.0
Oracle ≫ Utilities Framework Version 4.2.0.3.0
Oracle ≫ Utilities Framework Version 4.4.0.0.0
Oracle ≫ Utilities Framework Version 4.4.0.2.0
Oracle ≫ Webcenter Portal Version 11.1.1.9.0
Oracle ≫ Webcenter Portal Version 12.2.1.3.0
Oracle ≫ Webcenter Portal Version 12.2.1.4.0
Opensuse ≫ Leap Version 15.1
Netapp ≫ Snapcenter Version -
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.27% 0.936
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuapr2021.html
Patch
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1694235
Patch
Third Party Advisory
Issue Tracking
https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658
Patch
Third Party Advisory
https://github.com/dom4j/dom4j/commits/version-2.0.3
Patch
Third Party Advisory
https://github.com/dom4j/dom4j/issues/87
Third Party Advisory
https://github.com/dom4j/dom4j/releases/tag/version-2.1.3
Third Party Advisory
Release Notes
https://security.netapp.com/advisory/ntap-20200518-0002/
Third Party Advisory
https://usn.ubuntu.com/4575-1/
Third Party Advisory
https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
Third Party Advisory
https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E
https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E
https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E