CVE-2020-10683
01.05.2020, 19:15
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.Enginsight
Vendor | Product | Version |
---|---|---|
dom4j_project | dom4j | 𝑥 < 2.0.3 |
dom4j_project | dom4j | 2.1.0 ≤ 𝑥 < 2.1.3 |
oracle | agile_plm | 9.3.3 |
oracle | agile_plm | 9.3.5 |
oracle | application_testing_suite | 13.3.0.1 |
oracle | banking_platform | 2.4.0 ≤ 𝑥 ≤ 2.10.0 |
oracle | business_process_management_suite | 12.2.1.3.0 |
oracle | business_process_management_suite | 12.2.1.4.0 |
oracle | communications_application_session_controller | 3.9m0p1:m0p1 |
oracle | communications_diameter_signaling_router | 8.0.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_unified_inventory_management | 7.3.0 |
oracle | communications_unified_inventory_management | 7.4.0 |
oracle | data_integrator | 12.2.1.3.0 |
oracle | data_integrator | 12.2.1.4.0 |
oracle | documaker | 12.6.0 ≤ 𝑥 ≤ 12.6.4 |
oracle | endeca_information_discovery_integrator | 3.2.0 |
oracle | enterprise_data_quality | 11.1.1.9.0 |
oracle | enterprise_data_quality | 12.2.1.3.0 |
oracle | enterprise_manager_base_platform | 13.4.0.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | flexcube_core_banking | 11.7.0 |
oracle | flexcube_core_banking | 11.8.0 |
oracle | flexcube_core_banking | 11.9.0 |
oracle | flexcube_core_banking | 11.10.0 |
oracle | fusion_middleware | 12.2.1.4.0 |
oracle | health_sciences_empirica_signal | 9.0 |
oracle | health_sciences_information_manager | 3.0.1 |
oracle | insurance_policy_administration_j2ee | 11.1.0 ≤ 𝑥 ≤ 11.3.0 |
oracle | insurance_policy_administration_j2ee | 10.2.0 |
oracle | insurance_policy_administration_j2ee | 10.2.4 |
oracle | insurance_policy_administration_j2ee | 11.0.2 |
oracle | insurance_rules_palette | 11.1.0 ≤ 𝑥 ≤ 11.3.0 |
oracle | insurance_rules_palette | 10.2.0 |
oracle | insurance_rules_palette | 10.2.4 |
oracle | insurance_rules_palette | 11.0.2 |
oracle | jdeveloper | 12.2.1.4.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 16.1.0.0 ≤ 𝑥 ≤ 16.2.20.1 |
oracle | primavera_p6_enterprise_project_portfolio_management | 17.1.0.0 ≤ 𝑥 ≤ 17.12.17.1 |
oracle | primavera_p6_enterprise_project_portfolio_management | 18.1.0.0 ≤ 𝑥 ≤ 18.8.19.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 19.12.0.0 ≤ 𝑥 ≤ 19.12.6.0 |
oracle | rapid_planning | 12.1 |
oracle | rapid_planning | 12.2 |
oracle | retail_customer_management_and_segmentation_foundation | 16.0 |
oracle | retail_customer_management_and_segmentation_foundation | 17.0 |
oracle | retail_customer_management_and_segmentation_foundation | 18.0 |
oracle | retail_customer_management_and_segmentation_foundation | 19.0 |
oracle | retail_integration_bus | 15.0 |
oracle | retail_integration_bus | 16.0 |
oracle | retail_order_broker | 15.0 |
oracle | retail_order_broker | 16.0 |
oracle | retail_order_broker | 18.0 |
oracle | retail_order_broker | 19.0 |
oracle | retail_order_broker | 19.1 |
oracle | retail_price_management | 14.0.3 |
oracle | retail_price_management | 14.1.3.0 |
oracle | retail_price_management | 15.0.3.0 |
oracle | retail_price_management | 16.0.3.0 |
oracle | retail_xstore_point_of_service | 15.0.4 |
oracle | retail_xstore_point_of_service | 16.0.6 |
oracle | retail_xstore_point_of_service | 17.0.4 |
oracle | retail_xstore_point_of_service | 18.0.3 |
oracle | storagetek_tape_analytics_sw_tool | 2.3 |
oracle | utilities_framework | 4.3.0.1.0 ≤ 𝑥 ≤ 4.3.0.6.0 |
oracle | utilities_framework | 2.2.0.0.0 |
oracle | utilities_framework | 4.2.0.2.0 |
oracle | utilities_framework | 4.2.0.3.0 |
oracle | utilities_framework | 4.4.0.0.0 |
oracle | utilities_framework | 4.4.0.2.0 |
oracle | webcenter_portal | 11.1.1.9.0 |
oracle | webcenter_portal | 12.2.1.3.0 |
oracle | webcenter_portal | 12.2.1.4.0 |
opensuse | leap | 15.1 |
netapp | oncommand_api_services | - |
netapp | oncommand_workflow_automation | - |
netapp | snap_creator_framework | - |
netapp | snapcenter | - |
netapp | snapmanager | - |
netapp | snapmanager | - |
canonical | ubuntu_linux | 16.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References