← לוח פגיעויות

CVE-2020-25649

גבוהה 7.5

תיאור (מקור, אנגלית)

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS — סבירות ניצול
18% (אחוזון 100) נכון ל-17/9/2026
CWE
CWE-611

מוצרים מושפעים

fasterxml: jackson-databind; netapp: oncommand api services; netapp: oncommand workflow automation; netapp: service level manager; fedoraproject: fedora; quarkus: quarkus; apache: iotdb; oracle: agile product lifecycle management; oracle: agile product lifecycle management integration pack; oracle: banking apis; oracle: banking platform; oracle: banking treasury management; oracle: blockchain platform; oracle: coherence; oracle: commerce platform

קישורים