CVE-2020-10683
Last modified
CVE-2020-10683 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.. EPSS estimates a 7.27% chance of exploitation in the next 30 days.
Description
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dom4j Project | Dom4j | < 2.0.3 |
| Dom4j Project | Dom4j | >= 2.1.0, < 2.1.3 |
| Oracle | Agile Plm | 9.3.3 |
| Oracle | Agile Plm | 9.3.5 |
| Oracle | Application Testing Suite | 13.3.0.1 |
| Oracle | Banking Platform | >= 2.4.0, <= 2.10.0 |
| Oracle | Business Process Management Suite | 12.2.1.3.0 |
| Oracle | Business Process Management Suite | 12.2.1.4.0 |
| Oracle | Communications Application Session Controller | 3.9m0p1 |
| Oracle | Communications Diameter Signaling Router | >= 8.0.0, <= 8.2.2 |
| Oracle | Communications Unified Inventory Management | 7.3.0 |
| Oracle | Communications Unified Inventory Management | 7.4.0 |
| Oracle | Data Integrator | 12.2.1.3.0 |
| Oracle | Data Integrator | 12.2.1.4.0 |
| Oracle | Documaker | >= 12.6.0, <= 12.6.4 |
| Oracle | Endeca Information Discovery Integrator | 3.2.0 |
| Oracle | Enterprise Data Quality | 11.1.1.9.0 |
| Oracle | Enterprise Data Quality | 12.2.1.3.0 |
| Oracle | Enterprise Manager Base Platform | 13.4.0.0 |
| Oracle | Financial Services Analytical Applications Infrastructure | >= 8.0.6, <= 8.1.0 |
| Oracle | Flexcube Core Banking | 11.7.0 |
| Oracle | Flexcube Core Banking | 11.8.0 |
| Oracle | Flexcube Core Banking | 11.9.0 |
| Oracle | Flexcube Core Banking | 11.10.0 |
| Oracle | Fusion Middleware | 12.2.1.4.0 |
| Oracle | Health Sciences Empirica Signal | 9.0 |
| Oracle | Health Sciences Information Manager | 3.0.1 |
| Oracle | Insurance Policy Administration J2ee | >= 11.1.0, <= 11.3.0 |
| Oracle | Insurance Policy Administration J2ee | 10.2.0 |
| Oracle | Insurance Policy Administration J2ee | 10.2.4 |
| Oracle | Insurance Policy Administration J2ee | 11.0.2 |
| Oracle | Insurance Rules Palette | >= 11.1.0, <= 11.3.0 |
| Oracle | Insurance Rules Palette | 10.2.0 |
| Oracle | Insurance Rules Palette | 10.2.4 |
| Oracle | Insurance Rules Palette | 11.0.2 |
| Oracle | Jdeveloper | 12.2.1.4.0 |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | >= 16.1.0.0, <= 16.2.20.1 |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | >= 17.1.0.0, <= 17.12.17.1 |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | >= 18.1.0.0, <= 18.8.19.0 |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | >= 19.12.0.0, <= 19.12.6.0 |
| Oracle | Rapid Planning | 12.1 |
| Oracle | Rapid Planning | 12.2 |
| Oracle | Retail Customer Management And Segmentation Foundation | 16.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 17.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 18.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 19.0 |
| Oracle | Retail Integration Bus | 15.0 |
| Oracle | Retail Integration Bus | 16.0 |
| Oracle | Retail Order Broker | 15.0 |
| Oracle | Retail Order Broker | 16.0 |
Showing 50 of 78 affected configurations. See NVD for the full list.
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1694235Issue Tracking, Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/commits/version-2.0.3Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/issues/87Third Party Advisory
- https://github.com/dom4j/dom4j/releases/tag/version-2.1.3Release Notes, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200518-0002/Third Party Advisory
- https://usn.ubuntu.com/4575-1/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1694235Issue Tracking, Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/commits/version-2.0.3Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/issues/87Third Party Advisory
- https://github.com/dom4j/dom4j/releases/tag/version-2.1.3Release Notes, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200518-0002/Third Party Advisory
- https://usn.ubuntu.com/4575-1/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10683?
How severe is CVE-2020-10683?
How do I fix CVE-2020-10683?
Are you affected by CVE-2020-10683?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
