7.5

CVE-2020-25649

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FasterxmlJackson-databind Version >= 2.6.0 < 2.6.7.4
FasterxmlJackson-databind Version >= 2.9.0 < 2.9.10.7
FasterxmlJackson-databind Version >= 2.10.0 < 2.10.5.1
FedoraprojectFedora Version32
QuarkusQuarkus Version <= 1.6.1
ApacheIotdb Version < 0.12.0
OracleAgile Plm Version9.3.6
OracleAgile Product Lifecycle Management Integration Pack Version3.6 SwPlatforme-business_suite
OracleBanking Apis Version >= 18.1 <= 18.3
OracleBanking Apis Version19.1
OracleBanking Apis Version19.2
OracleBanking Apis Version20.1
OracleBanking Apis Version21.1
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.0
OracleBanking Platform Version2.7.1
OracleBanking Platform Version2.8.0
OracleBanking Platform Version2.9.0
OracleBanking Platform Version2.10.0
OracleBlockchain Platform Version < 21.1.2
OracleCoherence Version12.2.1.4.0
OracleCoherence Version14.1.1.0.0
OracleCommerce Platform Version >= 11.3.0 <= 11.3.2
OracleCommerce Platform Version11.2.0
OracleGoldengate Application Adapters Version19.1.0.0.0
OracleInsurance Policy Administration Version >= 11.1.0 <= 11.3.0
OracleInsurance Rules Palette Version >= 11.1.0 <= 11.3.0
OracleInsurance Rules Palette Version11.0.2
OracleJd Edwards Enterpriseone Tools Version < 9.2.5.3
OraclePrimavera Gateway Version >= 17.7 <= 17.12
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.11
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.10
OraclePrimavera Gateway Version20.12.0
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.3.1
OracleRetail Service Backbone Version16.0.3
OracleSd-wan Edge Version9.0
OracleUtilities Framework Version4.3.0.5.0
OracleUtilities Framework Version4.3.0.6.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleUtilities Framework Version4.4.0.3.0
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.01
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://bugzilla.redhat.com/show_bug.cgi?id=1887664
Third Party Advisory
Issue Tracking