35
CVE-2020-25649
—CVSS 3.1
7.5 high
EPSS
18%p97
Published
()
Modified
Description
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
- Vendors
- fasterxmlnetappfedoraprojectquarkusapacheoracle
- Products
- jackson-databind, oncommand api services, oncommand workflow automation, service level manager, fedora, quarkus, iotdb, agile product lifecycle management, agile product lifecycle management integration pack, banking apis, banking platform, banking treasury management
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N