CVE-2020-10683
Last modified
CVE-2020-10683 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.. EPSS estimates a 7.27% chance of exploitation in the next 30 days.
Description
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dom4j Project | Dom4j | < 2.0.3 |
| Dom4j Project | Dom4j | >= 2.1.0, < 2.1.3 |
| Oracle | Agile Plm | 9.3.3 |
| Oracle | Agile Plm | 9.3.5 |
| Oracle | Application Testing Suite | 13.3.0.1 |
| Oracle | Banking Platform | >= 2.4.0, <= 2.10.0 |
| Oracle | Business Process Management Suite | 12.2.1.3.0 |
| Oracle | Business Process Management Suite | 12.2.1.4.0 |
| Oracle | Communications Application Session Controller | 3.9m0p1 |
| Oracle | Communications Diameter Signaling Router | >= 8.0.0, <= 8.2.2 |
| Oracle | Communications Unified Inventory Management | 7.3.0 |
| Oracle | Communications Unified Inventory Management | 7.4.0 |
| Oracle | Data Integrator | 12.2.1.3.0 |
| Oracle | Data Integrator | 12.2.1.4.0 |
| Oracle | Documaker | >= 12.6.0, <= 12.6.4 |
| Oracle | Endeca Information Discovery Integrator | 3.2.0 |
| Oracle | Enterprise Data Quality | 11.1.1.9.0 |
| Oracle | Enterprise Data Quality | 12.2.1.3.0 |
| Oracle | Enterprise Manager Base Platform | 13.4.0.0 |
| Oracle | Financial Services Analytical Applications Infrastructure | >= 8.0.6, <= 8.1.0 |
| Oracle | Flexcube Core Banking | 11.7.0 |
| Oracle | Flexcube Core Banking | 11.8.0 |
| Oracle | Flexcube Core Banking | 11.9.0 |
| Oracle | Flexcube Core Banking | 11.10.0 |
| Oracle | Fusion Middleware | 12.2.1.4.0 |
| Oracle | Health Sciences Empirica Signal | 9.0 |
| Oracle | Health Sciences Information Manager | 3.0.1 |
| Oracle | Insurance Policy Administration J2ee | >= 11.1.0, <= 11.3.0 |
| Oracle | Insurance Policy Administration J2ee | 10.2.0 |
| Oracle | Insurance Policy Administration J2ee | 10.2.4 |
| Oracle | Insurance Policy Administration J2ee | 11.0.2 |
| Oracle | Insurance Rules Palette | >= 11.1.0, <= 11.3.0 |
| Oracle | Insurance Rules Palette | 10.2.0 |
| Oracle | Insurance Rules Palette | 10.2.4 |
| Oracle | Insurance Rules Palette | 11.0.2 |
| Oracle | Jdeveloper | 12.2.1.4.0 |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | >= 16.1.0.0, <= 16.2.20.1 |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | >= 17.1.0.0, <= 17.12.17.1 |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | >= 18.1.0.0, <= 18.8.19.0 |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | >= 19.12.0.0, <= 19.12.6.0 |
| Oracle | Rapid Planning | 12.1 |
| Oracle | Rapid Planning | 12.2 |
| Oracle | Retail Customer Management And Segmentation Foundation | 16.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 17.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 18.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 19.0 |
| Oracle | Retail Integration Bus | 15.0 |
| Oracle | Retail Integration Bus | 16.0 |
| Oracle | Retail Order Broker | 15.0 |
| Oracle | Retail Order Broker | 16.0 |
Showing 50 of 78 affected configurations. See NVD for the full list.
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1694235Issue Tracking, Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/commits/version-2.0.3Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/issues/87Third Party Advisory
- https://github.com/dom4j/dom4j/releases/tag/version-2.1.3Release Notes, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200518-0002/Third Party Advisory
- https://usn.ubuntu.com/4575-1/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1694235Issue Tracking, Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/commits/version-2.0.3Patch, Third Party Advisory
- https://github.com/dom4j/dom4j/issues/87Third Party Advisory
- https://github.com/dom4j/dom4j/releases/tag/version-2.1.3Release Notes, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200518-0002/Third Party Advisory
- https://usn.ubuntu.com/4575-1/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10683?
How severe is CVE-2020-10683?
How do I fix CVE-2020-10683?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10675The Library API in buger jsonparser through 2019-12-04 allow…7.5
- CVE-2020-10676In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an inco…8.8
- CVE-2020-10678In Octopus Deploy before 2020.1.5, for customers running on-…8.8
- CVE-2020-1068An elevation of privilege vulnerability exists in Windows Me…7.8
- CVE-2020-10681The Filemanager in CMS Made Simple 2.2.13 has stored XSS via…5.4
- CVE-2020-10682The Filemanager in CMS Made Simple 2.2.13 allows remote code…7.8
- CVE-2020-10684A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.…7.1
- CVE-2020-10685A flaw was found in Ansible Engine affecting Ansible Engine …5.5
- CVE-2020-10686A flaw was found in Keycloak version 8.0.2 and 9.0.0, and wa…4.7
- CVE-2020-10687A flaw was discovered in all versions of Undertow before Und…4.8
- CVE-2020-10688A cross-site scripting (XSS) flaw was found in RESTEasy in v…6.1
- CVE-2020-10689A flaw was found in the Eclipse Che up to version 7.8.x, whe…6.8
Are you affected by CVE-2020-10683?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
