CVE-2020-25020
published 2020-08-29CVE-2020-25020: MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.59%
83.6th percentile
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mpxj | mpxj | <= 8.1.3 | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | 17.7 – 17.12 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Restriction of XML External Entity Reference in MPXJ
osv·2021-05-07
CVE-2020-25020 [CRITICAL] Improper Restriction of XML External Entity Reference in MPXJ
Improper Restriction of XML External Entity Reference in MPXJ
"MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components."
GHSA
Improper Restriction of XML External Entity Reference in MPXJ
ghsa·2021-05-07
CVE-2020-25020 [CRITICAL] CWE-611 Improper Restriction of XML External Entity Reference in MPXJ
Improper Restriction of XML External Entity Reference in MPXJ
"MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components."
CISA ICS
Siemens COMOS
cisa_ics·2023-11-16·CVSS 9.8
[CRITICAL] Siemens COMOS
ICS Advisory
##
Siemens COMOS
Release DateNovember 16, 2023
Alert CodeICSA-23-320-09
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: COMOS
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Path Traversal, Out-of-bounds Write, Out-of-bounds Read, Integer Overflow or Wraparound, Use After Free, Heap-based Buffer Overflow, Cleartext Transmi
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Platform (MPXJ) — CVE-2020-25020
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2020-25020 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Platform (MPXJ) — CVE-2020-25020
Oracle Oracle Construction and Engineering Risk Matrix: Platform (MPXJ) vulnerability
CVE: CVE-2020-25020
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-08-29
Published