EXPOSURES › CVE-2020-10683
CVE-2020-10683
CRITICAL
DETAIL
SourceNVD · cve
Published2020-05-01
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-10683 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
NetApp · vendorOracle · vendorcanonical · vendordom4j project · vendoropensuse · vendorFusion Middleware · productagile product lifecycle management · productapplication testing suite · productbanking platform · productbusiness process management suite · productcommunications application session controller · productcommunications diameter signaling router · productcommunications unified inventory management · productdata integrator · productdocumaker · productdom4j · productendeca information discovery integrator · productenterprise data quality · productenterprise manager base platform · productfinancial services analytical applications infrastructure · productflexcube core banking · producthealth sciences empirica signal · producthealth sciences information manager · productinsurance policy administration j2ee · productinsurance rules palette · productjdeveloper · productleap · productoncommand api services · productoncommand workflow automation · productprimavera p6 enterprise project portfolio management · productrapid planning · productretail customer management and segmentation foundation · productretail integration bus · productretail order broker · productretail price management · productretail xstore point of service · productsnap creator framework · productsnapcenter · productsnapmanager · productstoragetek tape analytics sw tool · productubuntu linux · productutilities framework · productwebcenter portal · product
DESCRIPTION
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
SENTIMENT · TRUSTED SOURCES
synthesis
mixed
-0.20
Vulnerability acknowledged with available mitigation guidance.
Vulnerability acknowledged with available mitigation guidance.
"dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j."
AFFECTED FEDRAMP PRODUCTS · 11
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Cloud Insights NetApp |
In Process |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |