CVE-2020-10683
published 2020-05-01CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.27%
93.7th percentile
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | dom4j | < dom4j 2.1.3-1 (bookworm) | dom4j 2.1.3-1 (bookworm) |
| dom4j_project | dom4j | < 2.0.3 | 2.0.3 |
| dom4j_project | dom4j | >= 0 < 2.1.3-1 | 2.1.3-1 |
| dom4j_project | dom4j | >= 0 < 2.1.3-1 | 2.1.3-1 |
| dom4j_project | dom4j | >= 0 < 2.1.3-1 | 2.1.3-1 |
| dom4j_project | dom4j | >= 0 < 2.1.3-1 | 2.1.3-1 |
| dom4j_project | dom4j | >= 0 < 1.6.1+dfsg.3-2ubuntu1.1 | 1.6.1+dfsg.3-2ubuntu1.1 |
| dom4j_project | dom4j | >= 2.1.0 < 2.1.3 | 2.1.3 |
| opensuse | leap | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | application_testing_suite | — | — |
| oracle | banking_platform | 2.4.0 – 2.10.0 | — |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | communications_application_session_controller | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.2.2 | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | data_integrator | — | — |
| oracle | data_integrator | — | — |
| oracle | documaker | 12.6.0 – 12.6.4 | — |
| oracle | endeca_information_discovery_integrator | — | — |
| oracle | enterprise_data_quality | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Utilities Applications Risk Matrix: Content Acquisition System (dom4j) — CVE-2020-10683
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Utilities Applications Risk Matrix: Content Acquisition System (dom4j) — CVE-2020-10683
Oracle Oracle Utilities Applications Risk Matrix: Content Acquisition System (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Commerce Risk Matrix: Dynamo Application Framework (dom4j) — CVE-2020-10683
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Commerce Risk Matrix: Dynamo Application Framework (dom4j) — CVE-2020-10683
Oracle Oracle Commerce Risk Matrix: Dynamo Application Framework (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (dom4j) — CVE-2020-10683
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Commerce Risk Matrix: Content Acquisition System (dom4j) — CVE-2020-10683
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Architecture (dom4j) — CVE-2020-10683
vendor_oracle·2022-01-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Insurance Applications Risk Matrix: Architecture (dom4j) — CVE-2020-10683
Oracle Oracle Insurance Applications Risk Matrix: Architecture (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (dom4j) — CVE-2020-10683
vendor_oracle·2021-10-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (dom4j) — CVE-2020-10683
Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Mgmt (dom4j) — CVE-2020-10683
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Mgmt (dom4j) — CVE-2020-10683
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Mgmt (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (dom4j) — CVE-2020-10683
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (dom4j) — CVE-2020-10683
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (dom4j) — CVE-2020-10683
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (dom4j) — CVE-2020-10683
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (dom4j) — CVE-2020-10683
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Core (dom4j) — CVE-2020-10683
Oracle Oracle Communications Applications Risk Matrix: Core (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Ubuntu
dom4j vulnerability
vendor_ubuntu·2020-10-13·CVSS 9.8
CVE-2020-10683 [CRITICAL] dom4j vulnerability
Title: dom4j vulnerability
Summary: dom4j could be made to expose sensitive information or run programs if it
received specially crafted input.
It was discovered that dom4j incorrectly handled reading XML data. A
remote attacker could exploit this with a crafted XML file to expose
sensitive data or possibly execute arbitrary code. (CVE-2020-10683)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Web Access (dom4j) — CVE-2020-10683
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Web Access (dom4j) — CVE-2020-10683
Oracle Oracle Construction and Engineering Risk Matrix: Web Access (dom4j) vulnerability
CVE: CVE-2020-10683
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
dom4j: XML External Entity vulnerability in default SAX parser
vendor_redhat·2020-04-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] CWE-611 dom4j: XML External Entity vulnerability in default SAX parser
dom4j: XML External Entity vulnerability in default SAX parser
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Statement: OpenShift Container Platform ships a vulnerable version of dom4j library. However it's used to parse configuration files, which are local disk resources. We've rated this issue with a moderate impact for OpenShift Container Platform.
Package: dom4j (Red Hat BPM Suite 6) - Out of support scope
Package: dom4j (Red Hat Enterprise Linux 7) - Affected
Package: dom4j (Red Hat JBoss BRMS 5) - Out of support scope
Package: dom4j (Red Hat JBoss BR
Debian
CVE-2020-10683: dom4j - dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti...
vendor_debian·2020·CVSS 9.8
CVE-2020-10683 [CRITICAL] CVE-2020-10683: dom4j - dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti...
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Scope: local
bookworm: resolved (fixed in 2.1.3-1)
bullseye: resolved (fixed in 2.1.3-1)
forky: resolved (fixed in 2.1.3-1)
sid: resolved (fixed in 2.1.3-1)
trixie: resolved (fixed in 2.1.3-1)
OSV
dom4j vulnerability
osv·2020-10-13·CVSS 9.8
CVE-2020-10683 [CRITICAL] dom4j vulnerability
dom4j vulnerability
It was discovered that dom4j incorrectly handled reading XML data. A
remote attacker could exploit this with a crafted XML file to expose
sensitive data or possibly execute arbitrary code. (CVE-2020-10683)
OSV
dom4j allows External Entities by default which might enable XXE attacks
osv·2020-06-05
CVE-2020-10683 [CRITICAL] dom4j allows External Entities by default which might enable XXE attacks
dom4j allows External Entities by default which might enable XXE attacks
dom4j before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Note: This advisory applies to `dom4j:dom4j` version 1.x legacy artifacts. To resolve this a change to the latest version of `org.dom4j:dom4j` is recommended.
GHSA
dom4j allows External Entities by default which might enable XXE attacks
ghsa·2020-06-05
CVE-2020-10683 [CRITICAL] CWE-611 dom4j allows External Entities by default which might enable XXE attacks
dom4j allows External Entities by default which might enable XXE attacks
dom4j before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Note: This advisory applies to `dom4j:dom4j` version 1.x legacy artifacts. To resolve this a change to the latest version of `org.dom4j:dom4j` is recommended.
OSV
CVE-2020-10683: dom4j before 2
osv·2020-05-01·CVSS 9.8
CVE-2020-10683 [CRITICAL] CVE-2020-10683: dom4j before 2
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10683 dom4j: XML External Entity vulnerability in default SAX parser [fedora-all]
bugzilla·2020-04-15·CVSS 9.8
CVE-2020-10683 [CRITICAL] CVE-2020-10683 dom4j: XML External Entity vulnerability in default SAX parser [fedora-all]
CVE-2020-10683 dom4j: XML External Entity vulnerability in default SAX parser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2020-10683 dom4j: XML External Entity vulnerability in default SAX parser
bugzilla·2019-03-29·CVSS 9.8
CVE-2020-10683 [CRITICAL] CVE-2020-10683 dom4j: XML External Entity vulnerability in default SAX parser
CVE-2020-10683 dom4j: XML External Entity vulnerability in default SAX parser
A flaw was found in dom4j library. By using the default SaxReader() provided by Dom4J, external DTDs and External Entities are allowed, resulting in a possible XXE.
Discussion:
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Operations Network 3
* Red Hat JBoss Fuse Service Works 6
* Red Hat JBoss Fuse 6
* Red Hat JBoss SOA Platform 5
* Red Hat JBoss BRMS 6
* Red Hat JBoss BRMS 5
* Red Hat JBoss BPM Suite 6
* Red Hat Enterprise Application Platform 6
* Red Hat Enterprise Application Platform 5
* Red Hat JBoss Data Virtualization & Services 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
This vulnerability is
arXiv
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
arxiv_fulltext·2024-09-04
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
Fangyuan Zhang,
Lingling Fan*,
Sen Chen,
Miaoying Cai,
Sihan Xu,
and Lida Zhao
Fangyuan Zhang and Miaoying Cai are with DISSec, NDST, College of Computer Science, Nankai University, China. Emails: \fangyuanzhang, miaoyingcai\@mail.nankai.edu.cn.
Lingling Fan (Corresponding author) and Sihan Xu are with DISSec, NDST, College of Cyber Science, Nankai University, China. Emails: \linglingfan, xusihan\@nankai.edu.cn.
Sen Chen is with the College of Intelligence and Computing, Tianjin University, China. Email: [email protected].
Lida Zhao is with School of Computer Science and Engineering, Nanyang Technological University. Email: [email protected].
Journal of \ Class Files, Vol. XX,
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1694235https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.htmlhttps://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658https://github.com/dom4j/dom4j/commits/version-2.0.3https://github.com/dom4j/dom4j/issues/87https://github.com/dom4j/dom4j/releases/tag/version-2.1.3https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20200518-0002/https://usn.ubuntu.com/4575-1/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1694235https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.htmlhttps://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658https://github.com/dom4j/dom4j/commits/version-2.0.3https://github.com/dom4j/dom4j/issues/87https://github.com/dom4j/dom4j/releases/tag/version-2.1.3https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20200518-0002/https://usn.ubuntu.com/4575-1/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-05-01
Published