SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-6958

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.

CRITICAL 9.1EPSS 2.35%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS
2.35% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
yet another java service wrapper project/yet another java service wrapper
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.