7.5
CVE-2020-25649
- EPSS 0.01%
- Published 03.12.2020 17:15:12
- Last modified 21.11.2024 05:18:20
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
Data is provided by the National Vulnerability Database (NVD)
Fasterxml ≫ Jackson-databind Version >= 2.6.0 < 2.6.7.4
Fasterxml ≫ Jackson-databind Version >= 2.9.0 < 2.9.10.7
Fasterxml ≫ Jackson-databind Version >= 2.10.0 < 2.10.5.1
Netapp ≫ Oncommand Api Services Version-
Netapp ≫ Oncommand Workflow Automation Version-
Netapp ≫ Service Level Manager Version-
Fedoraproject ≫ Fedora Version32
Oracle ≫ Agile Product Lifecycle Management Integration Pack Version3.6 SwPlatforme-business_suite
Oracle ≫ Banking Apis Version >= 18.1 <= 18.3
Oracle ≫ Banking Apis Version19.1
Oracle ≫ Banking Apis Version19.2
Oracle ≫ Banking Apis Version20.1
Oracle ≫ Banking Apis Version21.1
Oracle ≫ Banking Platform Version2.6.2
Oracle ≫ Banking Platform Version2.7.0
Oracle ≫ Banking Platform Version2.7.1
Oracle ≫ Banking Platform Version2.8.0
Oracle ≫ Banking Platform Version2.9.0
Oracle ≫ Banking Platform Version2.10.0
Oracle ≫ Banking Treasury Management Version4.4
Oracle ≫ Blockchain Platform Version < 21.1.2
Oracle ≫ Commerce Platform Version >= 11.3.0 <= 11.3.2
Oracle ≫ Commerce Platform Version11.2.0
Oracle ≫ Communications Billing And Revenue Management Version7.5.0.23.0
Oracle ≫ Communications Billing And Revenue Management Version12.0.0.3.0
Oracle ≫ Communications Cloud Native Core Unified Data Repository Version1.4.0
Oracle ≫ Communications Convergent Charging Controller Version12.0.4.0.0
Oracle ≫ Communications Instant Messaging Server Version10.0.1.5.0
Oracle ≫ Communications Interactive Session Recorder Version6.3
Oracle ≫ Communications Interactive Session Recorder Version6.4
Oracle ≫ Communications Network Charging And Control Version12.0.4.0.0
Oracle ≫ Communications Offline Mediation Controller Version12.0.0.3
Oracle ≫ Communications Pricing Design Center Version12.0.0.4.0
Oracle ≫ Communications Services Gatekeeper Version7.0
Oracle ≫ Communications Unified Inventory Management Version7.4.1
Oracle ≫ Goldengate Application Adapters Version19.1.0.0.0
Oracle ≫ Health Sciences Empirica Signal Version9.0
Oracle ≫ Health Sciences Empirica Signal Version9.1
Oracle ≫ Insurance Policy Administration Version >= 11.1.0 <= 11.3.0
Oracle ≫ Insurance Policy Administration Version11.0.2
Oracle ≫ Insurance Rules Palette Version >= 11.1.0 <= 11.3.0
Oracle ≫ Insurance Rules Palette Version11.0.2
Oracle ≫ Jd Edwards Enterpriseone Orchestrator Version < 9.2.5.3
Oracle ≫ Jd Edwards Enterpriseone Tools Version < 9.2.5.3
Oracle ≫ Primavera Gateway Version >= 17.7 <= 17.12
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.11
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.11
Oracle ≫ Primavera Gateway Version >= 19.12.0 <= 19.12.10
Oracle ≫ Primavera Gateway Version20.12.0
Oracle ≫ Retail Service Backbone Version14.1.3.2
Oracle ≫ Retail Service Backbone Version15.0.3.1
Oracle ≫ Retail Service Backbone Version16.0.3
Oracle ≫ Retail Xstore Point Of Service Version16.0.6
Oracle ≫ Retail Xstore Point Of Service Version17.0.4
Oracle ≫ Retail Xstore Point Of Service Version18.0.3
Oracle ≫ Retail Xstore Point Of Service Version19.0.2
Oracle ≫ Retail Xstore Point Of Service Version20.0.1
Oracle ≫ Sd-wan Edge Version9.0
Oracle ≫ Utilities Framework Version4.3.0.5.0
Oracle ≫ Utilities Framework Version4.3.0.6.0
Oracle ≫ Utilities Framework Version4.4.0.0.0
Oracle ≫ Utilities Framework Version4.4.0.2.0
Oracle ≫ Utilities Framework Version4.4.0.3.0
Oracle ≫ Webcenter Portal Version12.2.1.3.0
Oracle ≫ Webcenter Portal Version12.2.1.4.0
Oracle ≫ Communications Messaging Server Version8.0.2
Oracle ≫ Communications Messaging Server Version8.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.01% | 0.01 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.