CVE-2020-25649
גבוהה 7.5
תיאור (מקור, אנגלית)
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - EPSS — סבירות ניצול
- 18% (אחוזון 100) נכון ל-17/9/2026
- CWE
- CWE-611
מוצרים מושפעים
fasterxml: jackson-databind; netapp: oncommand api services; netapp: oncommand workflow automation; netapp: service level manager; fedoraproject: fedora; quarkus: quarkus; apache: iotdb; oracle: agile product lifecycle management; oracle: agile product lifecycle management integration pack; oracle: banking apis; oracle: banking platform; oracle: banking treasury management; oracle: blockchain platform; oracle: coherence; oracle: commerce platform
קישורים
- https://github.com/FasterXML/jackson-databind/issues/2589 PatchThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
- https://github.com/FasterXML/jackson-databind/issues/2589 PatchThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory