peter bassill · operator
$ cve CVE-2020-10683 JSON

CVE-2020-10683

9.8
CRITICAL · CVSS 3.1 · EPSS 7.3% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.27% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploitnone known
Published2020-05-01
Last modified2026-08-25

Affected (38)

VendorProduct
canonicalubuntu linux
dom4j projectdom4j
netapponcommand api services
netapponcommand workflow automation
netappsnap creator framework
netappsnapcenter
netappsnapmanager
opensuseleap
oracleagile product lifecycle management
oracleapplication testing suite
oraclebanking platform
oraclebusiness process management suite
oraclecommunications application session controller
oraclecommunications diameter signaling router
oraclecommunications unified inventory management
oracledata integrator
oracledocumaker
oracleendeca information discovery integrator
oracleenterprise data quality
oracleenterprise manager base platform
oraclefinancial services analytical applications infrastructure
oracleflexcube core banking
oraclefusion middleware
oraclehealth sciences empirica signal
oraclehealth sciences information manager
oracleinsurance policy administration j2ee
oracleinsurance rules palette
oraclejdeveloper
oracleprimavera p6 enterprise project portfolio management
oraclerapid planning
oracleretail customer management and segmentation foundation
oracleretail integration bus
oracleretail order broker
oracleretail price management
oracleretail xstore point of service
oraclestoragetek tape analytics sw tool
oracleutilities framework
oraclewebcenter portal

References

→ the Explorer  ·  watch your stack  ·  NVD