ZeroHour

CVE-2020-25649

CVSS 3.1
7.5 high
EPSS
18%p97
Published
()
Modified
Description

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

Vendors
fasterxmlnetappfedoraprojectquarkusapacheoracle
Products
jackson-databind, oncommand api services, oncommand workflow automation, service level manager, fedora, quarkus, iotdb, agile product lifecycle management, agile product lifecycle management integration pack, banking apis, banking platform, banking treasury management
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news