CVE-2020-25649

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
VendorProductVersion
fasterxmljackson-databind
2.6.0 ≤
𝑥
< 2.6.7.4
fasterxmljackson-databind
2.9.0 ≤
𝑥
< 2.9.10.7
fasterxmljackson-databind
2.10.0 ≤
𝑥
< 2.10.5.1
netapponcommand_api_services
-
netapponcommand_workflow_automation
-
netappservice_level_manager
-
quarkusquarkus
𝑥
≤ 1.6.1
apacheiotdb
𝑥
< 0.12.0
oracleagile_plm
9.3.6
oracleagile_product_lifecycle_management_integration_pack
3.6
oraclebanking_apis
18.1 ≤
𝑥
≤ 18.3
oraclebanking_apis
19.1
oraclebanking_apis
19.2
oraclebanking_apis
20.1
oraclebanking_apis
21.1
oraclebanking_platform
2.6.2
oraclebanking_platform
2.7.0
oraclebanking_platform
2.7.1
oraclebanking_platform
2.8.0
oraclebanking_platform
2.9.0
oraclebanking_platform
2.10.0
oraclebanking_treasury_management
4.4
oracleblockchain_platform
𝑥
< 21.1.2
oraclecoherence
12.2.1.4.0
oraclecoherence
14.1.1.0.0
oraclecommerce_platform
11.3.0 ≤
𝑥
≤ 11.3.2
oraclecommerce_platform
11.2.0
oraclecommunications_billing_and_revenue_management
7.5.0.23.0
oraclecommunications_billing_and_revenue_management
12.0.0.3.0
oraclecommunications_cloud_native_core_unified_data_repository
1.4.0
oraclecommunications_convergent_charging_controller
12.0.4.0.0
oraclecommunications_evolved_communications_application_server
7.1
oraclecommunications_instant_messaging_server
10.0.1.5.0
oraclecommunications_interactive_session_recorder
6.3
oraclecommunications_interactive_session_recorder
6.4
oraclecommunications_network_charging_and_control
12.0.4.0.0
oraclecommunications_offline_mediation_controller
12.0.0.3
oraclecommunications_pricing_design_center
12.0.0.4.0
oraclecommunications_services_gatekeeper
7.0
oraclecommunications_unified_inventory_management
7.4.1
oraclegoldengate_application_adapters
19.1.0.0.0
oraclehealth_sciences_empirica_signal
9.0
oraclehealth_sciences_empirica_signal
9.1
oracleinsurance_policy_administration
11.1.0 ≤
𝑥
≤ 11.3.0
oracleinsurance_policy_administration
11.0.2
oracleinsurance_rules_palette
11.1.0 ≤
𝑥
≤ 11.3.0
oracleinsurance_rules_palette
11.0.2
oraclejd_edwards_enterpriseone_orchestrator
𝑥
< 9.2.5.3
oraclejd_edwards_enterpriseone_tools
𝑥
< 9.2.5.3
oracleprimavera_gateway
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.11
oracleprimavera_gateway
18.8.0 ≤
𝑥
≤ 18.8.11
oracleprimavera_gateway
19.12.0 ≤
𝑥
≤ 19.12.10
oracleprimavera_gateway
20.12.0
oracleretail_service_backbone
14.1.3.2
oracleretail_service_backbone
15.0.3.1
oracleretail_service_backbone
16.0.3
oracleretail_xstore_point_of_service
16.0.6
oracleretail_xstore_point_of_service
17.0.4
oracleretail_xstore_point_of_service
18.0.3
oracleretail_xstore_point_of_service
19.0.2
oracleretail_xstore_point_of_service
20.0.1
oraclesd-wan_edge
9.0
oracleutilities_framework
4.3.0.5.0
oracleutilities_framework
4.3.0.6.0
oracleutilities_framework
4.4.0.0.0
oracleutilities_framework
4.4.0.2.0
oracleutilities_framework
4.4.0.3.0
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
oraclecommunications_messaging_server
8.0.2
oraclecommunications_messaging_server
8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jackson-databind
bullseye (security)
2.12.1-1+deb11u1
fixed
bullseye
2.12.1-1+deb11u1
fixed
sid
2.14.0-1
fixed
trixie
2.14.0-1
fixed
bookworm
2.14.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jackson-databind
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
needed
bionic
needed
xenial
needed
trusty
needs-triage
References