9.8

CVE-2020-10683

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dom4j ProjectDom4j Version < 2.0.3
Dom4j ProjectDom4j Version >= 2.1.0 < 2.1.3
OracleAgile Plm Version9.3.3
OracleAgile Plm Version9.3.5
OracleApplication Testing Suite Version13.3.0.1
OracleBanking Platform Version >= 2.4.0 <= 2.10.0
OracleCommunications Diameter Signaling Router Version >= 8.0.0 <= 8.2.2
OracleData Integrator Version12.2.1.3.0
OracleData Integrator Version12.2.1.4.0
OracleDocumaker Version >= 12.6.0 <= 12.6.4
OracleEnterprise Data Quality Version11.1.1.9.0
OracleEnterprise Data Quality Version12.2.1.3.0
OracleFlexcube Core Banking Version11.7.0
OracleFlexcube Core Banking Version11.8.0
OracleFlexcube Core Banking Version11.9.0
OracleFlexcube Core Banking Version11.10.0
OracleFusion Middleware Version12.2.1.4.0
OracleInsurance Policy Administration J2ee Version >= 11.1.0 <= 11.3.0
OracleInsurance Rules Palette Version >= 11.1.0 <= 11.3.0
OracleInsurance Rules Palette Version10.2.0
OracleInsurance Rules Palette Version10.2.4
OracleInsurance Rules Palette Version11.0.2
OracleJdeveloper Version12.2.1.4.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 16.1.0.0 <= 16.2.20.1
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 17.1.0.0 <= 17.12.17.1
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 18.1.0.0 <= 18.8.19.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 19.12.0.0 <= 19.12.6.0
OracleRapid Planning Version12.1
OracleRapid Planning Version12.2
OracleRetail Integration Bus Version15.0
OracleRetail Integration Bus Version16.0
OracleRetail Order Broker Version15.0
OracleRetail Order Broker Version16.0
OracleRetail Order Broker Version18.0
OracleRetail Order Broker Version19.0
OracleRetail Order Broker Version19.1
OracleRetail Price Management Version14.0.3
OracleRetail Price Management Version14.1.3.0
OracleRetail Price Management Version15.0.3.0
OracleRetail Price Management Version16.0.3.0
OracleUtilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
OracleUtilities Framework Version2.2.0.0.0
OracleUtilities Framework Version4.2.0.2.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleWebcenter Portal Version11.1.1.9.0
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
OpensuseLeap Version15.1
NetappSnapcenter Version-
NetappSnapmanager Version- SwPlatformoracle
NetappSnapmanager Version- SwPlatformsap
CanonicalUbuntu Linux Version16.04 SwEditionesm
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.96% 0.829
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://bugzilla.redhat.com/show_bug.cgi?id=1694235
Patch
Third Party Advisory
Issue Tracking
https://usn.ubuntu.com/4575-1/
Third Party Advisory