{"id":"CVE-2020-10683","title":"dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks","summary":"dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default beha…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-611"],"vendor":"dom4j_project","product":"dom4j","affected":["dom4j < 2.0.3","dom4j >= 2.1.0, < 2.1.3","agile_product_lifecycle_management = 9.3.3","agile_product_lifecycle_management = 9.3.5","application_testing_suite = 13.3.0.1","banking_platform >= 2.4.0, <= 2.10.0","business_process_management_suite = 12.2.1.3.0","business_process_management_suite = 12.2.1.4.0","communications_application_session_controller = 3.9m0p1","communications_diameter_signaling_router >= 8.0.0, <= 8.2.2","communications_unified_inventory_management = 7.3.0","communications_unified_inventory_management = 7.4.0","data_integrator = 12.2.1.3.0","data_integrator = 12.2.1.4.0","documaker >= 12.6.0, <= 12.6.4","endeca_information_discovery_integrator = 3.2.0","enterprise_data_quality = 11.1.1.9.0","enterprise_data_quality = 12.2.1.3.0","enterprise_manager_base_platform = 13.4.0.0","financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.0","flexcube_core_banking = 11.7.0","flexcube_core_banking = 11.8.0","flexcube_core_banking = 11.9.0","flexcube_core_banking = 11.10.0","fusion_middleware = 12.2.1.4.0","health_sciences_empirica_signal = 9.0","health_sciences_information_manager = 3.0.1","insurance_policy_administration_j2ee >= 11.1.0, <= 11.3.0","insurance_policy_administration_j2ee = 10.2.0","insurance_policy_administration_j2ee = 10.2.4","insurance_policy_administration_j2ee = 11.0.2","insurance_rules_palette >= 11.1.0, <= 11.3.0","insurance_rules_palette = 10.2.0","insurance_rules_palette = 10.2.4","insurance_rules_palette = 11.0.2","jdeveloper = 12.2.1.4.0","primavera_p6_enterprise_project_portfolio_management >= 16.1.0.0, <= 16.2.20.1","primavera_p6_enterprise_project_portfolio_management >= 17.1.0.0, <= 17.12.17.1","primavera_p6_enterprise_project_portfolio_management >= 18.1.0.0, <= 18.8.19.0","primavera_p6_enterprise_project_portfolio_management >= 19.12.0.0, <= 19.12.6.0","rapid_planning = 12.1","rapid_planning = 12.2","retail_customer_management_and_segmentation_foundation = 16.0","retail_customer_management_and_segmentation_foundation = 17.0","retail_customer_management_and_segmentation_foundation = 18.0","retail_customer_management_and_segmentation_foundation = 19.0","retail_integration_bus = 15.0","retail_integration_bus = 16.0","retail_order_broker = 15.0","retail_order_broker = 16.0","retail_order_broker = 18.0","retail_order_broker = 19.0","retail_order_broker = 19.1","retail_price_management = 14.0.3","retail_price_management = 14.1.3.0","retail_price_management = 15.0.3.0","retail_price_management = 16.0.3.0","retail_xstore_point_of_service = 15.0.4","retail_xstore_point_of_service = 16.0.6","retail_xstore_point_of_service = 17.0.4","retail_xstore_point_of_service = 18.0.3","storagetek_tape_analytics_sw_tool = 2.3","utilities_framework >= 4.3.0.1.0, <= 4.3.0.6.0","utilities_framework = 2.2.0.0.0","utilities_framework = 4.2.0.2.0","utilities_framework = 4.2.0.3.0","utilities_framework = 4.4.0.0.0","utilities_framework = 4.4.0.2.0","webcenter_portal = 11.1.1.9.0","webcenter_portal = 12.2.1.3.0","webcenter_portal = 12.2.1.4.0","leap = 15.1","oncommand_api_services","oncommand_workflow_automation","snap_creator_framework","snapcenter","snapmanager","ubuntu_linux = 16.04"],"patched":["dom4j 2.1.3"],"published":"2020-05-01","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-10683","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html","label":"cve@mitre.org"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1694235","label":"cve@mitre.org"},{"url":"https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html","label":"cve@mitre.org"},{"url":"https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658","label":"cve@mitre.org"},{"url":"https://github.com/dom4j/dom4j/commits/version-2.0.3","label":"cve@mitre.org"},{"url":"https://github.com/dom4j/dom4j/issues/87","label":"cve@mitre.org"},{"url":"https://github.com/dom4j/dom4j/releases/tag/version-2.1.3","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20200518-0002/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4575-1/","label":"cve@mitre.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1694235","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/dom4j/dom4j/commits/version-2.0.3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/dom4j/dom4j/issues/87","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/dom4j/dom4j/releases/tag/version-2.1.3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200518-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4575-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.07269,"epssPercentile":0.94157,"ingestedAt":"2026-08-25T17:29:29.946Z","slug":"CVE-2020-10683","body":"## Overview\n\ndom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.\n\n## Affected\n\n- `dom4j < 2.0.3`\n- `dom4j >= 2.1.0, < 2.1.3`\n- `agile_product_lifecycle_management = 9.3.3`\n- `agile_product_lifecycle_management = 9.3.5`\n- `application_testing_suite = 13.3.0.1`\n- `banking_platform >= 2.4.0, <= 2.10.0`\n- `business_process_management_suite = 12.2.1.3.0`\n- `business_process_management_suite = 12.2.1.4.0`\n- `communications_application_session_controller = 3.9m0p1`\n- `communications_diameter_signaling_router >= 8.0.0, <= 8.2.2`\n- `communications_unified_inventory_management = 7.3.0`\n- `communications_unified_inventory_management = 7.4.0`\n- `data_integrator = 12.2.1.3.0`\n- `data_integrator = 12.2.1.4.0`\n- `documaker >= 12.6.0, <= 12.6.4`\n- `endeca_information_discovery_integrator = 3.2.0`\n- `enterprise_data_quality = 11.1.1.9.0`\n- `enterprise_data_quality = 12.2.1.3.0`\n- `enterprise_manager_base_platform = 13.4.0.0`\n- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.0`\n- `flexcube_core_banking = 11.7.0`\n- `flexcube_core_banking = 11.8.0`\n- `flexcube_core_banking = 11.9.0`\n- `flexcube_core_banking = 11.10.0`\n- `fusion_middleware = 12.2.1.4.0`\n- `health_sciences_empirica_signal = 9.0`\n- `health_sciences_information_manager = 3.0.1`\n- `insurance_policy_administration_j2ee >= 11.1.0, <= 11.3.0`\n- `insurance_policy_administration_j2ee = 10.2.0`\n- `insurance_policy_administration_j2ee = 10.2.4`\n- `insurance_policy_administration_j2ee = 11.0.2`\n- `insurance_rules_palette >= 11.1.0, <= 11.3.0`\n- `insurance_rules_palette = 10.2.0`\n- `insurance_rules_palette = 10.2.4`\n- `insurance_rules_palette = 11.0.2`\n- `jdeveloper = 12.2.1.4.0`\n- `primavera_p6_enterprise_project_portfolio_management >= 16.1.0.0, <= 16.2.20.1`\n- `primavera_p6_enterprise_project_portfolio_management >= 17.1.0.0, <= 17.12.17.1`\n- `primavera_p6_enterprise_project_portfolio_management >= 18.1.0.0, <= 18.8.19.0`\n- `primavera_p6_enterprise_project_portfolio_management >= 19.12.0.0, <= 19.12.6.0`\n- `rapid_planning = 12.1`\n- `rapid_planning = 12.2`\n- `retail_customer_management_and_segmentation_foundation = 16.0`\n- `retail_customer_management_and_segmentation_foundation = 17.0`\n- `retail_customer_management_and_segmentation_foundation = 18.0`\n- `retail_customer_management_and_segmentation_foundation = 19.0`\n- `retail_integration_bus = 15.0`\n- `retail_integration_bus = 16.0`\n- `retail_order_broker = 15.0`\n- `retail_order_broker = 16.0`\n- `retail_order_broker = 18.0`\n- `retail_order_broker = 19.0`\n- `retail_order_broker = 19.1`\n- `retail_price_management = 14.0.3`\n- `retail_price_management = 14.1.3.0`\n- `retail_price_management = 15.0.3.0`\n- `retail_price_management = 16.0.3.0`\n- `retail_xstore_point_of_service = 15.0.4`\n- `retail_xstore_point_of_service = 16.0.6`\n- `retail_xstore_point_of_service = 17.0.4`\n- `retail_xstore_point_of_service = 18.0.3`\n- `storagetek_tape_analytics_sw_tool = 2.3`\n- `utilities_framework >= 4.3.0.1.0, <= 4.3.0.6.0`\n- `utilities_framework = 2.2.0.0.0`\n- `utilities_framework = 4.2.0.2.0`\n- `utilities_framework = 4.2.0.3.0`\n- `utilities_framework = 4.4.0.0.0`\n- `utilities_framework = 4.4.0.2.0`\n- `webcenter_portal = 11.1.1.9.0`\n- `webcenter_portal = 12.2.1.3.0`\n- `webcenter_portal = 12.2.1.4.0`\n- `leap = 15.1`\n- `oncommand_api_services`\n- `oncommand_workflow_automation`\n- `snap_creator_framework`\n- `snapcenter`\n- `snapmanager`\n- `ubuntu_linux = 16.04`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `dom4j 2.1.3`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":53.9,"likelihood":1.5,"exploitation":0,"ransomware":0},"changes":[]}