CVE-2020-25020

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 0.21 % (59th)
0.21% Progress
Affected Products 2
Advisories 1

MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

Weaknesses
CWE-611
Improper Restriction of XML External Entity Reference
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2020-08-29 19:15:14
(4 years ago)
Updated Date
2022-09-02 15:29:44
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mpxj 8.1.3 and prior versions cpe:2.3:a:mpxj:mpxj <= 8.1.3

Configuration #2

    CPE23 From Up To
  Oracle Primavera Unifier from 17.7 version and 17.12 and prior versions cpe:2.3:a:oracle:primavera_unifier >= 17.7 <= 17.12
  Oracle Primavera Unifier 16.1 cpe:2.3:a:oracle:primavera_unifier:16.1
  Oracle Primavera Unifier 16.2 cpe:2.3:a:oracle:primavera_unifier:16.2
  Oracle Primavera Unifier 18.8 cpe:2.3:a:oracle:primavera_unifier:18.8
  Oracle Primavera Unifier 19.12 cpe:2.3:a:oracle:primavera_unifier:19.12
  Oracle Primavera Unifier 20.12 cpe:2.3:a:oracle:primavera_unifier:20.12
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...