CVE-2020-10683Critical· 9.8▾ Midnightdom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default beha…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.3%
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
dom4j < 2.0.3dom4j >= 2.1.0, < 2.1.3agile_product_lifecycle_management = 9.3.3agile_product_lifecycle_management = 9.3.5application_testing_suite = 13.3.0.1banking_platform >= 2.4.0, <= 2.10.0business_process_management_suite = 12.2.1.3.0business_process_management_suite = 12.2.1.4.0communications_application_session_controller = 3.9m0p1communications_diameter_signaling_router >= 8.0.0, <= 8.2.2communications_unified_inventory_management = 7.3.0communications_unified_inventory_management = 7.4.0data_integrator = 12.2.1.3.0data_integrator = 12.2.1.4.0documaker >= 12.6.0, <= 12.6.4endeca_information_discovery_integrator = 3.2.0enterprise_data_quality = 11.1.1.9.0enterprise_data_quality = 12.2.1.3.0enterprise_manager_base_platform = 13.4.0.0financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.0flexcube_core_banking = 11.7.0flexcube_core_banking = 11.8.0flexcube_core_banking = 11.9.0flexcube_core_banking = 11.10.0fusion_middleware = 12.2.1.4.0health_sciences_empirica_signal = 9.0health_sciences_information_manager = 3.0.1insurance_policy_administration_j2ee >= 11.1.0, <= 11.3.0insurance_policy_administration_j2ee = 10.2.0insurance_policy_administration_j2ee = 10.2.4insurance_policy_administration_j2ee = 11.0.2insurance_rules_palette >= 11.1.0, <= 11.3.0insurance_rules_palette = 10.2.0insurance_rules_palette = 10.2.4insurance_rules_palette = 11.0.2jdeveloper = 12.2.1.4.0primavera_p6_enterprise_project_portfolio_management >= 16.1.0.0, <= 16.2.20.1primavera_p6_enterprise_project_portfolio_management >= 17.1.0.0, <= 17.12.17.1primavera_p6_enterprise_project_portfolio_management >= 18.1.0.0, <= 18.8.19.0primavera_p6_enterprise_project_portfolio_management >= 19.12.0.0, <= 19.12.6.0rapid_planning = 12.1rapid_planning = 12.2retail_customer_management_and_segmentation_foundation = 16.0retail_customer_management_and_segmentation_foundation = 17.0retail_customer_management_and_segmentation_foundation = 18.0retail_customer_management_and_segmentation_foundation = 19.0retail_integration_bus = 15.0retail_integration_bus = 16.0retail_order_broker = 15.0retail_order_broker = 16.0retail_order_broker = 18.0retail_order_broker = 19.0retail_order_broker = 19.1retail_price_management = 14.0.3retail_price_management = 14.1.3.0retail_price_management = 15.0.3.0retail_price_management = 16.0.3.0retail_xstore_point_of_service = 15.0.4retail_xstore_point_of_service = 16.0.6retail_xstore_point_of_service = 17.0.4retail_xstore_point_of_service = 18.0.3storagetek_tape_analytics_sw_tool = 2.3utilities_framework >= 4.3.0.1.0, <= 4.3.0.6.0utilities_framework = 2.2.0.0.0utilities_framework = 4.2.0.2.0utilities_framework = 4.2.0.3.0utilities_framework = 4.4.0.0.0utilities_framework = 4.4.0.2.0webcenter_portal = 11.1.1.9.0webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0leap = 15.1oncommand_api_servicesoncommand_workflow_automationsnap_creator_frameworksnapcentersnapmanagerubuntu_linux = 16.04Upgrade past the affected range:
dom4j 2.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2019-3773Critical· 9.8Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
CVE-2020-25649High· 7.5A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly
CVE-2018-1259High· 7.5Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity refer…
CVE-2019-3774Critical· 9.8Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
CVE-2026-12975High· 8.5A flaw was found in Apicurio Registry
CVE-2026-94108Medium· 6.5getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0