← All CVEs

CVE-2020-25649

high · 7.5

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

7.5
CVSS
17.8%
EPSS (exploit prob.)
97th
EPSS percentile
2020-12-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-611

Affected products

VendorProductAffected versions
fasterxmljackson-databind>= 2.6.0, < 2.6.7.4
fasterxmljackson-databind>= 2.9.0, < 2.9.10.7
fasterxmljackson-databind>= 2.10.0, < 2.10.5.1
netapponcommand_api_servicesall versions
netapponcommand_workflow_automationall versions
netappservice_level_managerall versions
fedoraprojectfedora32
quarkusquarkus<= 1.6.1
apacheiotdb< 0.12.0
oracleagile_product_lifecycle_management9.3.6
oracleagile_product_lifecycle_management_integration_pack3.6
oraclebanking_apis>= 18.1, <= 18.3
oraclebanking_apis19.1
oraclebanking_apis19.2
oraclebanking_apis20.1
oraclebanking_apis21.1
oraclebanking_platform2.6.2
oraclebanking_platform2.7.0
oraclebanking_platform2.7.1
oraclebanking_platform2.8.0
oraclebanking_platform2.9.0
oraclebanking_platform2.10.0
oraclebanking_treasury_management4.4
oracleblockchain_platform< 21.1.2
oraclecoherence12.2.1.4.0
oraclecoherence14.1.1.0.0
oraclecommerce_platform>= 11.3.0, <= 11.3.2
oraclecommerce_platform11.2.0
oraclecommunications_billing_and_revenue_management7.5.0.23.0
oraclecommunications_billing_and_revenue_management12.0.0.3.0
oraclecommunications_cloud_native_core_unified_data_repository1.4.0
oraclecommunications_convergent_charging_controller12.0.4.0.0
oraclecommunications_evolved_communications_application_server7.1
oraclecommunications_instant_messaging_server10.0.1.5.0
oraclecommunications_interactive_session_recorder6.3
oraclecommunications_interactive_session_recorder6.4
oraclecommunications_network_charging_and_control12.0.4.0.0
oraclecommunications_offline_mediation_controller12.0.0.3
oraclecommunications_pricing_design_center12.0.0.4.0
oraclecommunications_services_gatekeeper7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-25649