CVE-2020-14621
published 2020-07-15CVE-2020-14621: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
4.35%
90.2th percentile
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-11 | < openjdk-11 11.0.8+10-1 (bullseye) | openjdk-11 11.0.8+10-1 (bullseye) |
| debian | openjdk-8 | < openjdk-11 11.0.8+10-1 (bullseye) | openjdk-11 11.0.8+10-1 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mcafee | epolicy_orchestrator | — | — |
| mcafee | epolicy_orchestrator | — | — |
| mcafee | epolicy_orchestrator | — | — |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.70.2 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | openjdk | — | — |
| oracle | openjdk | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
vendor_redhat·2020-08-27·CVSS 5.3
CVE-2020-14338 [MEDIUM] CWE-20 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipul
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2020-08-05·CVSS 4.8
CVE-2020-14556 [MEDIUM] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
Johannes Kuhn discovered that OpenJDK 8 incorrectly handled access control
contexts. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2020-14556)
Philippe Arteau discovered that OpenJDK 8 incorrectly verified names in
TLS server's X.509 certificates. An attacker could possibly use this
issue to obtain sensitive information. (CVE-2020-14577)
It was discovered that OpenJDK 8 incorrectly handled exceptions in
DerInputStream class and in the DerValue.equals() method. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2020-14578, CVE-2020-14579)
It was discovered that OpenJDK 8 incorrectly handled image files. An
attacker could possibly use this issu
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2020-07-23·CVSS 4.8
CVE-2020-14556 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Johannes Kuhn discovered that OpenJDK incorrectly handled access control
contexts. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2020-14556)
It was discovered that OpenJDK incorrectly handled memory allocation when
reading TIFF image files. An attacker could possibly use this issue to
cause a denial of service. (CVE-2020-14562)
It was discovered that OpenJDK incorrectly handled input data. An
attacker could possibly use this issue to insert, edit or obtain
sensitive information. (CVE-2020-14573)
Philippe Arteau discovered that OpenJDK incorrectly verified names in
TLS server's X.509 certificates. An attacker could possibly use this
issue to obtain sensitive information. (
Oracle
Oracle Oracle Java SE Risk Matrix: JAXP — CVE-2020-14621
vendor_oracle·2020-07-15·CVSS 5.3
CVE-2020-14621 [MEDIUM] Oracle Oracle Java SE Risk Matrix: JAXP — CVE-2020-14621
Oracle Oracle Java SE Risk Matrix: JAXP vulnerability
CVE: CVE-2020-14621
CVSS: 5.3
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
OpenJDK: XML validation manipulation due to incomplete application of the use-grammar-pool-only feature (JAXP, 8242136)
vendor_redhat·2020-07-14·CVSS 5.3
CVE-2020-14621 [MEDIUM] CWE-20 OpenJDK: XML validation manipulation due to incomplete application of the use-grammar-pool-only feature (JAXP, 8242136)
OpenJDK: XML validation manipulation due to incomplete application of the use-grammar-pool-only feature (JAXP, 8242136)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applet
Debian
CVE-2020-14621: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...
vendor_debian·2020·CVSS 5.3
CVE-2020-14621 [MEDIUM] CVE-2020-14621: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N
GHSA
GHSA-p493-cq87-mf78: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP)
ghsa_unreviewed·2022-05-24
CVE-2020-14621 [MEDIUM] GHSA-p493-cq87-mf78: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N
GHSA
Improper Input Validation in Xerces
ghsa·2022-02-15·CVSS 5.3
CVE-2020-14338 [MEDIUM] CWE-20 Improper Input Validation in Xerces
Improper Input Validation in Xerces
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. All xerces jboss versions before 2.12.0.SP3.
OSV
Improper Input Validation in Xerces
osv·2022-02-15·CVSS 5.3
CVE-2020-14338 [MEDIUM] Improper Input Validation in Xerces
Improper Input Validation in Xerces
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. All xerces jboss versions before 2.12.0.SP3.
OSV
openjdk-8 vulnerabilities
osv·2020-08-05·CVSS 4.8
CVE-2020-14556 [MEDIUM] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
Johannes Kuhn discovered that OpenJDK 8 incorrectly handled access control
contexts. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2020-14556)
Philippe Arteau discovered that OpenJDK 8 incorrectly verified names in
TLS server's X.509 certificates. An attacker could possibly use this
issue to obtain sensitive information. (CVE-2020-14577)
It was discovered that OpenJDK 8 incorrectly handled exceptions in
DerInputStream class and in the DerValue.equals() method. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2020-14578, CVE-2020-14579)
It was discovered that OpenJDK 8 incorrectly handled image files. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2020-14581)
Markus Loewe
OSV
openjdk-lts vulnerabilities
osv·2020-07-23·CVSS 4.8
CVE-2020-14556 [MEDIUM] openjdk-lts vulnerabilities
openjdk-lts vulnerabilities
Johannes Kuhn discovered that OpenJDK incorrectly handled access control
contexts. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2020-14556)
It was discovered that OpenJDK incorrectly handled memory allocation when
reading TIFF image files. An attacker could possibly use this issue to
cause a denial of service. (CVE-2020-14562)
It was discovered that OpenJDK incorrectly handled input data. An
attacker could possibly use this issue to insert, edit or obtain
sensitive information. (CVE-2020-14573)
Philippe Arteau discovered that OpenJDK incorrectly verified names in
TLS server's X.509 certificates. An attacker could possibly use this
issue to obtain sensitive information. (CVE-2020-14577)
It was discovered that OpenJDK incorrectly
OSV
CVE-2020-14621: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP)
osv·2020-07-15·CVSS 5.3
CVE-2020-14621 [MEDIUM] CVE-2020-14621: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14338 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
bugzilla·2020-07-23·CVSS 5.3
CVE-2020-14338 [MEDIUM] CVE-2020-14338 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
CVE-2020-14338 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
A flaw was found in Wildfly's implementation of xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. A specially-crafted XML file could possibly use this flaw to manipulate with the validation process in certain cases. This is the same flaw as CVE-2020-14621, which affected OpenJDK, which uses similar code.
Discussion:
*** Bug 1860076 has been marked as a duplicate of this bug. ***
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Enterprise Application Platform 5
* Red Hat JBoss Enterprise Application Platform 6
* Red Hat JBoss Da
Bugzilla
CVE-2020-14621 OpenJDK: XML validation manipulation due to incomplete application of the use-grammar-pool-only feature (JAXP, 8242136)
bugzilla·2020-07-14·CVSS 5.3
CVE-2020-14621 [MEDIUM] CVE-2020-14621 OpenJDK: XML validation manipulation due to incomplete application of the use-grammar-pool-only feature (JAXP, 8242136)
CVE-2020-14621 OpenJDK: XML validation manipulation due to incomplete application of the use-grammar-pool-only feature (JAXP, 8242136)
A flaw was found in the way the XMLSchemaValidator class in the JAXP component of OpenJDK enforced the "use-grammar-pool-only" feature. A specially-crafted XML file could possibly use this flaw to manipulate with the validation process in certain cases.
Discussion:
Public now via Oracle CPU July 2020:
https://www.oracle.com/security-alerts/cpujul2020.html#AppendixJAVA
Fixed in Oracle Java SE 14.0.2, 11.0.8, 8u261, and 7u271.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:2970 https://access.redhat.com/errata/RHSA-2020:2970
---
This issue has been addressed in the following products:
Red Hat
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10332https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/08/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/https://security.gentoo.org/glsa/202008-24https://security.gentoo.org/glsa/202209-15https://security.netapp.com/advisory/ntap-20200717-0005/https://usn.ubuntu.com/4433-1/https://usn.ubuntu.com/4453-1/https://www.debian.org/security/2020/dsa-4734https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10332https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/08/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/https://security.gentoo.org/glsa/202008-24https://security.gentoo.org/glsa/202209-15https://security.netapp.com/advisory/ntap-20200717-0005/https://usn.ubuntu.com/4433-1/https://usn.ubuntu.com/4453-1/https://www.debian.org/security/2020/dsa-4734https://www.oracle.com/security-alerts/cpujul2020.html
2020-07-15
Published