HIGH · 7.5

CVE-2020-25649

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from th...

Vulnerability Description

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
FasterxmlJackson-Databind>= 2.6.0, < 2.6.7.4
NetappOncommand Api Services-
NetappOncommand Workflow Automation-
NetappService Level Manager-
FedoraprojectFedora32
QuarkusQuarkus<= 1.6.1
ApacheIotdb< 0.12.0
OracleAgile Plm9.3.6
OracleAgile Product Lifecycle Management Integration Pack3.6
OracleBanking Apis>= 18.1, <= 18.3
OracleBanking Platform2.6.2
OracleBanking Treasury Management4.4
OracleBlockchain Platform< 21.1.2
OracleCoherence12.2.1.4.0
OracleCommerce Platform>= 11.3.0, <= 11.3.2
OracleCommunications Billing And Revenue Management7.5.0.23.0
OracleCommunications Cloud Native Core Unified Data Repository1.4.0
OracleCommunications Convergent Charging Controller12.0.4.0.0
OracleCommunications Evolved Communications Application Server7.1
OracleCommunications Instant Messaging Server10.0.1.5.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-25649?

CVE-2020-25649 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from th...

How severe is CVE-2020-25649?

CVE-2020-25649 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-25649?

Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind, Netapp Oncommand Api Services, Netapp Oncommand Workflow Automation, Netapp Service Level Manager, Fedoraproject Fedora.