Vulnerability Description
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mpxj | Mpxj | < 8.3.5 |
| Oracle | Primavera Unifier | >= 17.7, <= 17.12 |
Related Weaknesses (CWE)
References
- http://www.mpxj.org/changes-report.html#a8.3.5Release NotesVendor Advisory
- https://github.com/joniles/mpxj/commit/8eaf4225048ea5ba7e59ef4556dab2098fcc4a1dPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatchThird Party Advisory
- http://www.mpxj.org/changes-report.html#a8.3.5Release NotesVendor Advisory
- https://github.com/joniles/mpxj/commit/8eaf4225048ea5ba7e59ef4556dab2098fcc4a1dPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatchThird Party Advisory
FAQ
What is CVE-2020-35460?
CVE-2020-35460 is a vulnerability with a CVSS score of 5.3 (MEDIUM). common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
How severe is CVE-2020-35460?
CVE-2020-35460 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35460?
Check the references section above for vendor advisories and patch information. Affected products include: Mpxj Mpxj, Oracle Primavera Unifier.