Логотип exploitDog
bind:CVE-2020-14338
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-14338

Количество 5

Количество 5

redhat логотип

CVE-2020-14338

больше 5 лет назад

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-14338

больше 5 лет назад

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-14338

больше 5 лет назад

A flaw was found in Wildfly's implementation of Xerces, specifically i ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-w4jq-qh47-hvjq

почти 4 года назад

Improper Input Validation in Xerces

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2020-04150

больше 5 лет назад

Уязвимость класса XMLSchemaValidator компонента JAXP программного средства WildFly (JBoss Application Server), позволяющая нарушителю получить доступ на чтение, изменение, добавление или удаление данных с помощью многочисленных сетевых протоколов

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-14338

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-14338

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-14338

A flaw was found in Wildfly's implementation of Xerces, specifically i ...

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
github логотип
GHSA-w4jq-qh47-hvjq

Improper Input Validation in Xerces

CVSS3: 5.3
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2020-04150

Уязвимость класса XMLSchemaValidator компонента JAXP программного средства WildFly (JBoss Application Server), позволяющая нарушителю получить доступ на чтение, изменение, добавление или удаление данных с помощью многочисленных сетевых протоколов

CVSS3: 5.3
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу