← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-10683

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:7.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
dom4j_project dom4j all
oracle agile_plm 9.3.3, 9.3.5
oracle application_testing_suite 13.3.0.1
oracle banking_platform all
oracle business_process_management_suite 12.2.1.3.0, 12.2.1.4.0
oracle communications_application_session_controller 3.9m0p1
oracle communications_diameter_signaling_router all
oracle communications_unified_inventory_management 7.3.0, 7.4.0
oracle data_integrator 12.2.1.3.0, 12.2.1.4.0
oracle documaker all
oracle endeca_information_discovery_integrator 3.2.0
oracle enterprise_data_quality 11.1.1.9.0, 12.2.1.3.0
oracle enterprise_manager_base_platform 13.4.0.0
oracle financial_services_analytical_applications_infrastructure all
oracle flexcube_core_banking 11.7.0, 11.8.0, 11.9.0, 11.10.0
oracle fusion_middleware 12.2.1.4.0
oracle health_sciences_empirica_signal 9.0
oracle health_sciences_information_manager 3.0.1
oracle insurance_policy_administration_j2ee 10.2.0, 10.2.4, 11.0.2
oracle insurance_rules_palette 10.2.0, 10.2.4, 11.0.2
oracle jdeveloper 12.2.1.4.0
oracle primavera_p6_enterprise_project_portfolio_management all
oracle rapid_planning 12.1, 12.2
oracle retail_customer_management_and_segmentation_foundation 16.0, 17.0, 18.0, 19.0
oracle retail_integration_bus 15.0, 16.0
oracle retail_order_broker 15.0, 16.0, 18.0, 19.0, 19.1
oracle retail_price_management 14.0.3, 14.1.3.0, 15.0.3.0, 16.0.3.0
oracle retail_xstore_point_of_service 15.0.4, 16.0.6, 17.0.4, 18.0.3
oracle storagetek_tape_analytics_sw_tool 2.3
oracle utilities_framework 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.4.0.0.0, 4.4.0.2.0
oracle webcenter_portal 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0
opensuse leap 15.1
netapp oncommand_api_services all
netapp oncommand_workflow_automation all
netapp snap_creator_framework all
netapp snapcenter all
netapp snapmanager all
canonical ubuntu_linux 16.04

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
7.269%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-03-20T00:00:00
Published2020-05-01T18:55:25
Patch Date2020-04-12
Last Updated2024-08-04T11:06:11

LINK COPIED TO CLIPBOARD