V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
BDU:2020-04038
BDU
Critical

Уязвимость реализации функции new org.dom4j.io.SAXReader() библиотеки для работы с XML, XPath и XSLT dom4j связана с неверным ограничением …

CVSS
9.8
Critical
EPSS
0.00
p0
Published
2020-01-01
Updated
2020-01-01
Description

Уязвимость реализации функции new org.dom4j.io.SAXReader() библиотеки для работы с XML, XPath и XSLT dom4j связана с неверным ограничением XML-ссылок на внешние объекты. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, получить несанкционированный доступ к защищаемой информации

Tags · CWE
Pre-auth
Affected products
Google inc Android studioGoogle inc Android studioGoogle inc Android studioGoogle inc Android studioOracle corp. Application testing suiteOracle corp. Application testing suiteOracle corp. Application testing suiteOracle corp. Application testing suiteOracle corp. Banking platformOracle corp. Banking platformOracle corp. Banking platformOracle corp. Banking platformOracle corp. Business process management suiteOracle corp. Business process management suiteOracle corp. Business process management suiteOracle corp. Business process management suiteOracle corp. Business process management suiteOracle corp. Business process management suiteOracle corp. Business process management suiteOracle corp. Business process management suite
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
android studiogoogle incTracked
android studiogoogle incTracked
android studiogoogle incTracked
android studiogoogle incTracked
application testing suiteoracle corp.Tracked
application testing suiteoracle corp.Tracked
application testing suiteoracle corp.Tracked
application testing suiteoracle corp.Tracked
banking platformoracle corp.Tracked
banking platformoracle corp.Tracked
banking platformoracle corp.Tracked
banking platformoracle corp.Tracked
business process management suiteoracle corp.Tracked
business process management suiteoracle corp.Tracked
business process management suiteoracle corp.Tracked
business process management suiteoracle corp.Tracked
business process management suiteoracle corp.Tracked
business process management suiteoracle corp.Tracked
business process management suiteoracle corp.Tracked
business process management suiteoracle corp.Tracked
Showing first 20 of 248