dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Metrics
- CVSS v4.0 N/A
- CVSS v3.1 9.8 Critical
- CVSS v3.0 7.4 High
- CVSS v2 7.5 High
- KEV no
- EPSS 0.07684
- SSVC no
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.07684.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Dom4j Project
Subscribe
|
Dom4j
Subscribe
|
|
Netapp
Subscribe
|
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Oracle
Subscribe
|
Agile Plm
Subscribe
Application Testing Suite
Subscribe
Banking Platform
Subscribe
Business Process Management Suite
Subscribe
Communications Application Session Controller
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Unified Inventory Management
Subscribe
Data Integrator
Subscribe
Documaker
Subscribe
Endeca Information Discovery Integrator
Subscribe
Enterprise Data Quality
Subscribe
Enterprise Manager Base Platform
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Flexcube Core Banking
Subscribe
Fusion Middleware
Subscribe
Health Sciences Empirica Signal
Subscribe
Health Sciences Information Manager
Subscribe
Insurance Policy Administration J2ee
Subscribe
Insurance Rules Palette
Subscribe
Jdeveloper
Subscribe
Primavera P6 Enterprise Project Portfolio Management
Subscribe
Rapid Planning
Subscribe
Retail Customer Management And Segmentation Foundation
Subscribe
Retail Integration Bus
Subscribe
Retail Order Broker
Subscribe
Retail Price Management
Subscribe
Retail Xstore Point Of Service
Subscribe
Storagetek Tape Analytics Sw Tool
Subscribe
Utilities Framework
Subscribe
Webcenter Portal
Subscribe
|
|
Redhat
Subscribe
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
Configuration 5 [-]
|
| Package | CPE | Advisory | Released Date |
|---|---|---|---|
| EAP-CD 20 Tech Preview | |||
| dom4j | cpe:/a:redhat:jboss_enterprise_application_platform_cd:20 | RHSA-2020:3585 | 2020-08-31T00:00:00Z |
| Red Hat Fuse 7.8.0 | |||
| dom4j | cpe:/a:redhat:jboss_fuse:7 | RHSA-2020:5568 | 2020-12-16T00:00:00Z |
| Red Hat JBoss Enterprise Application Platform 7 | |||
| dom4j | cpe:/a:redhat:jboss_enterprise_application_platform:7.2.0 | RHSA-2020:3642 | 2020-09-07T00:00:00Z |
| dom4j | cpe:/a:redhat:jboss_enterprise_application_platform:7.3.0 | RHSA-2020:3464 | 2020-08-17T00:00:00Z |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | |||
| eap7-dom4j-0:2.1.3-1.redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-elytron-web-0:1.2.5-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-glassfish-jsf-0:2.3.5-13.SP3_redhat_00011.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-hal-console-0:3.0.23-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-jackson-databind-0:2.9.10.4-1.redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-jboss-jsf-api_2.3_spec-0:2.3.5-7.SP2_redhat_00005.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-jboss-modules-0:1.8.10-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-jboss-server-migration-0:1.3.1-13.Final_redhat_00014.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-jboss-xnio-base-0:3.7.6-4.SP3_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-resteasy-0:3.6.1-10.SP9_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-weld-core-0:3.0.6-4.Final_redhat_00004.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-wildfly-0:7.2.9-4.GA_redhat_00003.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-wildfly-elytron-0:1.6.8-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| eap7-wildfly-transaction-client-0:1.1.11-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6 | RHSA-2020:3637 | 2020-09-07T00:00:00Z |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | |||
| eap7-dom4j-0:2.1.3-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-elytron-web-0:1.2.5-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-glassfish-jsf-0:2.3.5-13.SP3_redhat_00011.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-hal-console-0:3.0.23-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-jackson-databind-0:2.9.10.4-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-jboss-jsf-api_2.3_spec-0:2.3.5-7.SP2_redhat_00005.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-jboss-modules-0:1.8.10-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-jboss-server-migration-0:1.3.1-13.Final_redhat_00014.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-jboss-xnio-base-0:3.7.6-4.SP3_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-resteasy-0:3.6.1-10.SP9_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-weld-core-0:3.0.6-4.Final_redhat_00004.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-wildfly-0:7.2.9-4.GA_redhat_00003.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-wildfly-elytron-0:1.6.8-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| eap7-wildfly-transaction-client-0:1.1.11-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7 | RHSA-2020:3638 | 2020-09-07T00:00:00Z |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | |||
| eap7-dom4j-0:2.1.3-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-elytron-web-0:1.2.5-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-glassfish-jsf-0:2.3.5-13.SP3_redhat_00011.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-hal-console-0:3.0.23-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-jackson-databind-0:2.9.10.4-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-jboss-jsf-api_2.3_spec-0:2.3.5-7.SP2_redhat_00005.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-jboss-modules-0:1.8.10-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-jboss-server-migration-0:1.3.1-13.Final_redhat_00014.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-jboss-xnio-base-0:3.7.6-4.SP3_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-resteasy-0:3.6.1-10.SP9_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-weld-core-0:3.0.6-4.Final_redhat_00004.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-wildfly-0:7.2.9-4.GA_redhat_00003.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-wildfly-elytron-0:1.6.8-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| eap7-wildfly-transaction-client-0:1.1.11-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8 | RHSA-2020:3639 | 2020-09-07T00:00:00Z |
| Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | |||
| eap7-dom4j-0:2.1.3-1.redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-elytron-web-0:1.6.2-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-glassfish-jsf-0:2.3.9-11.SP11_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-hal-console-0:3.2.9-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-infinispan-0:9.4.19-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jackson-annotations-0:2.10.4-1.redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jackson-core-0:2.10.4-1.redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jackson-databind-0:2.10.4-1.redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jackson-jaxrs-providers-0:2.10.4-1.redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jackson-modules-base-0:2.10.4-1.redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jackson-modules-java8-0:2.10.4-1.redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jboss-jsf-api_2.3_spec-0:3.0.0-4.SP04_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jboss-server-migration-0:1.7.1-7.Final_redhat_00009.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-jboss-xnio-base-0:3.7.8-1.SP1_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-netty-0:4.1.48-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-wildfly-0:7.3.2-4.GA_redhat_00002.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-wildfly-common-0:1.5.2-1.Final_redhat_00002.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-wildfly-elytron-0:1.10.7-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el6eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6 | RHSA-2020:3461 | 2020-08-17T00:00:00Z |
| Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | |||
| eap7-dom4j-0:2.1.3-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-elytron-web-0:1.6.2-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-glassfish-jsf-0:2.3.9-11.SP11_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-hal-console-0:3.2.9-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-infinispan-0:9.4.19-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jackson-annotations-0:2.10.4-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jackson-core-0:2.10.4-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jackson-databind-0:2.10.4-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jackson-jaxrs-providers-0:2.10.4-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jackson-modules-base-0:2.10.4-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jackson-modules-java8-0:2.10.4-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jboss-jsf-api_2.3_spec-0:3.0.0-4.SP04_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jboss-server-migration-0:1.7.1-7.Final_redhat_00009.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-jboss-xnio-base-0:3.7.8-1.SP1_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-netty-0:4.1.48-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-wildfly-0:7.3.2-4.GA_redhat_00002.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-wildfly-common-0:1.5.2-1.Final_redhat_00002.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-wildfly-elytron-0:1.10.7-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7 | RHSA-2020:3462 | 2020-08-17T00:00:00Z |
| Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | |||
| eap7-dom4j-0:2.1.3-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-elytron-web-0:1.6.2-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-glassfish-jsf-0:2.3.9-11.SP11_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-hal-console-0:3.2.9-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-infinispan-0:9.4.19-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jackson-annotations-0:2.10.4-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jackson-core-0:2.10.4-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jackson-databind-0:2.10.4-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jackson-jaxrs-providers-0:2.10.4-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jackson-modules-base-0:2.10.4-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jackson-modules-java8-0:2.10.4-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jboss-jsf-api_2.3_spec-0:3.0.0-4.SP04_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jboss-server-migration-0:1.7.1-7.Final_redhat_00009.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-jboss-xnio-base-0:3.7.8-1.SP1_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-netty-0:4.1.48-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-wildfly-0:7.3.2-4.GA_redhat_00002.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-wildfly-common-0:1.5.2-1.Final_redhat_00002.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-wildfly-elytron-0:1.10.7-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8 | RHSA-2020:3463 | 2020-08-17T00:00:00Z |
| Red Hat Single Sign-On 7.4.2 | |||
| dom4j | cpe:/a:redhat:jboss_single_sign_on:7.4 | RHSA-2020:3501 | 2020-08-18T00:00:00Z |
| RHDM 7.9.0 | |||
| dom4j | cpe:/a:redhat:jboss_enterprise_brms_platform:7.9 | RHSA-2020:4960 | 2020-11-05T00:00:00Z |
| RHPAM 7.9.0 | |||
| dom4j | cpe:/a:redhat:jboss_enterprise_bpms_platform:7.9 | RHSA-2020:4961 | 2020-11-05T00:00:00Z |
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2191-1 | dom4j security update |
EUVD |
EUVD-2020-0492 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j. |
Github GHSA |
GHSA-hwj3-m3p6-hj38 | dom4j allows External Entities by default which might enable XXE attacks |
Ubuntu USN |
USN-4575-1 | dom4j vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:06:11.156Z
Reserved: 2020-03-20T00:00:00
Link: CVE-2020-10683
No data.
Status : Modified
Published: 2020-05-01T19:15:12.927
Modified: 2024-11-21T04:55:50.587
Link: CVE-2020-10683
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN