CVE-2020-25649
high · 7.5A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
7.5
CVSS
17.8%
EPSS (exploit prob.)
97th
EPSS percentile
2020-12-03
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-611
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fasterxml | jackson-databind | >= 2.6.0, < 2.6.7.4 |
| fasterxml | jackson-databind | >= 2.9.0, < 2.9.10.7 |
| fasterxml | jackson-databind | >= 2.10.0, < 2.10.5.1 |
| netapp | oncommand_api_services | all versions |
| netapp | oncommand_workflow_automation | all versions |
| netapp | service_level_manager | all versions |
| fedoraproject | fedora | 32 |
| quarkus | quarkus | <= 1.6.1 |
| apache | iotdb | < 0.12.0 |
| oracle | agile_product_lifecycle_management | 9.3.6 |
| oracle | agile_product_lifecycle_management_integration_pack | 3.6 |
| oracle | banking_apis | >= 18.1, <= 18.3 |
| oracle | banking_apis | 19.1 |
| oracle | banking_apis | 19.2 |
| oracle | banking_apis | 20.1 |
| oracle | banking_apis | 21.1 |
| oracle | banking_platform | 2.6.2 |
| oracle | banking_platform | 2.7.0 |
| oracle | banking_platform | 2.7.1 |
| oracle | banking_platform | 2.8.0 |
| oracle | banking_platform | 2.9.0 |
| oracle | banking_platform | 2.10.0 |
| oracle | banking_treasury_management | 4.4 |
| oracle | blockchain_platform | < 21.1.2 |
| oracle | coherence | 12.2.1.4.0 |
| oracle | coherence | 14.1.1.0.0 |
| oracle | commerce_platform | >= 11.3.0, <= 11.3.2 |
| oracle | commerce_platform | 11.2.0 |
| oracle | communications_billing_and_revenue_management | 7.5.0.23.0 |
| oracle | communications_billing_and_revenue_management | 12.0.0.3.0 |
| oracle | communications_cloud_native_core_unified_data_repository | 1.4.0 |
| oracle | communications_convergent_charging_controller | 12.0.4.0.0 |
| oracle | communications_evolved_communications_application_server | 7.1 |
| oracle | communications_instant_messaging_server | 10.0.1.5.0 |
| oracle | communications_interactive_session_recorder | 6.3 |
| oracle | communications_interactive_session_recorder | 6.4 |
| oracle | communications_network_charging_and_control | 12.0.4.0.0 |
| oracle | communications_offline_mediation_controller | 12.0.0.3 |
| oracle | communications_pricing_design_center | 12.0.0.4.0 |
| oracle | communications_services_gatekeeper | 7.0 |
Check a specific version with /api/v1/cve/match.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1887664
- https://github.com/FasterXML/jackson-databind/issues/2589
- https://lists.apache.org/thread.html/r011d1430e8f40dff9550c3bc5d0f48b14c01ba8aecabd91d5e495386%40%3Ccommits.turbine.apache.org%3E
- https://lists.apache.org/thread.html/r024b7bda9c43c5560d81238748775c5ecfe01b57280f90df1f773949%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r04529cedaca40c2ff90af4880493f9c88a8ebf4d1d6c861d23108a5a%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r0881e23bd9034c8f51fdccdc8f4d085ba985dcd738f8520569ca5c3d%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r0b8dc3acd4503e4ecb6fbd6ea7d95f59941168d8452ac0ab1d1d96bb%40%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r1b7ed0c4b6c4301d4dfd6fdbc5581b0a789d3240cab55d766f33c6c6%40%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r2882fc1f3032cd7be66e28787f04ec6f1874ac68d47e310e30ff7eb1%40%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r2b6ddb3a4f4cd11d8f6305011e1b7438ba813511f2e3ab3180c7ffda%40%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r2eb66c182853c69ecfb52f63d3dec09495e9b65be829fd889a081ae1%40%3Cdev.hive.apache.org%3E
- https://lists.apache.org/thread.html/r2f5c5479f99398ef344b7ebd4d90bc3316236c45d0f3bc42090efcd7%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r31f4ee7d561d56a0c2c2c6eb1d6ce3e05917ff9654fdbfec05dc2b83%40%3Ccommits.servicecomb.apache.org%3E
- https://lists.apache.org/thread.html/r3e6ae311842de4e64c5d560a475b7f9cc7e0a9a8649363c6cf7537eb%40%3Ccommits.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r407538adec3185dd35a05c9a26ae2f74425b15132470cf540f41d85b%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r45e7350dfc92bb192f3f88e9971c11ab2be0953cc375be3dda5170bd%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r5b130fe668503c4b7e2caf1b16f86b7f2070fd1b7ef8f26195a2ffbd%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r5f8a1608d758936bd6bbc5eed980777437b611537bf6fff40663fc71%40%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r605764e05e201db33b3e9c2e66ff620658f07ad74f296abe483f7042%40%3Creviews.iotdb.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r63c87aab97155f3f3cbe11d030c4a184ea0de440ee714977db02e956%40%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r68d029ee74ab0f3b0569d0c05f5688cb45dd3abe96a6534735252805%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r6a4f3ef6edfed2e0884269d84798f766779bbbc1005f7884e0800d61%40%3Cdev.knox.apache.org%3E
- https://lists.apache.org/thread.html/r6a6df5647583541e3cb71c75141008802f7025cee1c430d4ed78f4cc%40%3Cissues.hive.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-25649