{
    "id": "CVE-2020-10683",
    "published": "2020-05-01 19:15:12",
    "last_modified": "2026-08-25 16:28:27",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-611",
    "description": "dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.",
    "epss_score": "0.07269",
    "epss_percentile": "0.94177",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-05 18:17:21",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "canonical",
            "product": "ubuntu_linux"
        },
        {
            "vendor": "dom4j_project",
            "product": "dom4j"
        },
        {
            "vendor": "netapp",
            "product": "oncommand_api_services"
        },
        {
            "vendor": "netapp",
            "product": "oncommand_workflow_automation"
        },
        {
            "vendor": "netapp",
            "product": "snap_creator_framework"
        },
        {
            "vendor": "netapp",
            "product": "snapcenter"
        },
        {
            "vendor": "netapp",
            "product": "snapmanager"
        },
        {
            "vendor": "opensuse",
            "product": "leap"
        },
        {
            "vendor": "oracle",
            "product": "agile_product_lifecycle_management"
        },
        {
            "vendor": "oracle",
            "product": "application_testing_suite"
        },
        {
            "vendor": "oracle",
            "product": "banking_platform"
        },
        {
            "vendor": "oracle",
            "product": "business_process_management_suite"
        },
        {
            "vendor": "oracle",
            "product": "communications_application_session_controller"
        },
        {
            "vendor": "oracle",
            "product": "communications_diameter_signaling_router"
        },
        {
            "vendor": "oracle",
            "product": "communications_unified_inventory_management"
        },
        {
            "vendor": "oracle",
            "product": "data_integrator"
        },
        {
            "vendor": "oracle",
            "product": "documaker"
        },
        {
            "vendor": "oracle",
            "product": "endeca_information_discovery_integrator"
        },
        {
            "vendor": "oracle",
            "product": "enterprise_data_quality"
        },
        {
            "vendor": "oracle",
            "product": "enterprise_manager_base_platform"
        },
        {
            "vendor": "oracle",
            "product": "financial_services_analytical_applications_infrastructure"
        },
        {
            "vendor": "oracle",
            "product": "flexcube_core_banking"
        },
        {
            "vendor": "oracle",
            "product": "fusion_middleware"
        },
        {
            "vendor": "oracle",
            "product": "health_sciences_empirica_signal"
        },
        {
            "vendor": "oracle",
            "product": "health_sciences_information_manager"
        },
        {
            "vendor": "oracle",
            "product": "insurance_policy_administration_j2ee"
        },
        {
            "vendor": "oracle",
            "product": "insurance_rules_palette"
        },
        {
            "vendor": "oracle",
            "product": "jdeveloper"
        },
        {
            "vendor": "oracle",
            "product": "primavera_p6_enterprise_project_portfolio_management"
        },
        {
            "vendor": "oracle",
            "product": "rapid_planning"
        },
        {
            "vendor": "oracle",
            "product": "retail_customer_management_and_segmentation_foundation"
        },
        {
            "vendor": "oracle",
            "product": "retail_integration_bus"
        },
        {
            "vendor": "oracle",
            "product": "retail_order_broker"
        },
        {
            "vendor": "oracle",
            "product": "retail_price_management"
        },
        {
            "vendor": "oracle",
            "product": "retail_xstore_point_of_service"
        },
        {
            "vendor": "oracle",
            "product": "storagetek_tape_analytics_sw_tool"
        },
        {
            "vendor": "oracle",
            "product": "utilities_framework"
        },
        {
            "vendor": "oracle",
            "product": "webcenter_portal"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html",
        "https://bugzilla.redhat.com/show_bug.cgi?id=1694235",
        "https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html",
        "https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658",
        "https://github.com/dom4j/dom4j/commits/version-2.0.3",
        "https://github.com/dom4j/dom4j/issues/87",
        "https://github.com/dom4j/dom4j/releases/tag/version-2.1.3",
        "https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E",
        "https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E",
        "https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E",
        "https://security.netapp.com/advisory/ntap-20200518-0002/",
        "https://usn.ubuntu.com/4575-1/",
        "https://www.oracle.com//security-alerts/cpujul2021.html",
        "https://www.oracle.com/security-alerts/cpuApr2021.html",
        "https://www.oracle.com/security-alerts/cpujan2021.html",
        "https://www.oracle.com/security-alerts/cpujan2022.html",
        "https://www.oracle.com/security-alerts/cpujul2020.html",
        "https://www.oracle.com/security-alerts/cpujul2022.html",
        "https://www.oracle.com/security-alerts/cpuoct2020.html",
        "https://www.oracle.com/security-alerts/cpuoct2021.html",
        "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html",
        "https://bugzilla.redhat.com/show_bug.cgi?id=1694235",
        "https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html",
        "https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658",
        "https://github.com/dom4j/dom4j/commits/version-2.0.3"
    ]
}