CRITICAL · 9.8

CVE-2020-10683

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how...

Vulnerability Description

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Dom4J ProjectDom4J< 2.0.3
OracleAgile Plm9.3.3
OracleApplication Testing Suite13.3.0.1
OracleBanking Platform>= 2.4.0, <= 2.10.0
OracleBusiness Process Management Suite12.2.1.3.0
OracleCommunications Application Session Controller3.9m0p1
OracleCommunications Diameter Signaling Router>= 8.0.0, <= 8.2.2
OracleCommunications Unified Inventory Management7.3.0
OracleData Integrator12.2.1.3.0
OracleDocumaker>= 12.6.0, <= 12.6.4
OracleEndeca Information Discovery Integrator3.2.0
OracleEnterprise Data Quality11.1.1.9.0
OracleEnterprise Manager Base Platform13.4.0.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6, <= 8.1.0
OracleFlexcube Core Banking11.7.0
OracleFusion Middleware12.2.1.4.0
OracleHealth Sciences Empirica Signal9.0
OracleHealth Sciences Information Manager3.0.1
OracleInsurance Policy Administration J2Ee>= 11.1.0, <= 11.3.0
OracleInsurance Rules Palette>= 11.1.0, <= 11.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-10683?

CVE-2020-10683 is a vulnerability with a CVSS score of 9.8 (CRITICAL). dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how...

How severe is CVE-2020-10683?

CVE-2020-10683 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-10683?

Check the references section above for vendor advisories and patch information. Affected products include: Dom4J Project Dom4J, Oracle Agile Plm, Oracle Application Testing Suite, Oracle Banking Platform, Oracle Business Process Management Suite.