SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-25649

This flaw allows vulnerability to XML external entity (XXE) attacks.

HIGH 7.5EPSS 17.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 17.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
17.81% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
fasterxml/jackson-databind · netapp/oncommand api services · netapp/oncommand workflow automation · netapp/service level manager · fedoraproject/fedora · quarkus/quarkus · apache/iotdb · oracle/agile product lifecycle management · oracle/agile product lifecycle management integration pack · oracle/banking apis · oracle/banking platform · oracle/banking treasury management · oracle/blockchain platform · oracle/coherence · oracle/commerce platform · oracle/communications billing and revenue management · oracle/communications cloud native core unified data repository · oracle/communications convergent charging controller · oracle/communications evolved communications application server · oracle/communications instant messaging server · +19 more
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.