CRITICAL · 9.1

CVE-2020-6958

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially c...

Vulnerability Description

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Yet Another Java Service Wrapper ProjectYet Another Java Service Wrapper12.14

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-6958?

CVE-2020-6958 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially c...

How severe is CVE-2020-6958?

CVE-2020-6958 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-6958?

Check the references section above for vendor advisories and patch information. Affected products include: Yet Another Java Service Wrapper Project Yet Another Java Service Wrapper.