---
id: CVE-2020-10683
title: >-
  dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External
  Entities by default, which might enable XXE attacks
summary: >-
  dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External
  Entities by default, which might enable XXE attacks. However, there is popular
  external documentation from OWASP showing how to enable the safe, non-default
  beha…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-611
vendor: dom4j_project
product: dom4j
affected:
  - dom4j < 2.0.3
  - 'dom4j >= 2.1.0, < 2.1.3'
  - agile_product_lifecycle_management = 9.3.3
  - agile_product_lifecycle_management = 9.3.5
  - application_testing_suite = 13.3.0.1
  - 'banking_platform >= 2.4.0, <= 2.10.0'
  - business_process_management_suite = 12.2.1.3.0
  - business_process_management_suite = 12.2.1.4.0
  - communications_application_session_controller = 3.9m0p1
  - 'communications_diameter_signaling_router >= 8.0.0, <= 8.2.2'
  - communications_unified_inventory_management = 7.3.0
  - communications_unified_inventory_management = 7.4.0
  - data_integrator = 12.2.1.3.0
  - data_integrator = 12.2.1.4.0
  - 'documaker >= 12.6.0, <= 12.6.4'
  - endeca_information_discovery_integrator = 3.2.0
  - enterprise_data_quality = 11.1.1.9.0
  - enterprise_data_quality = 12.2.1.3.0
  - enterprise_manager_base_platform = 13.4.0.0
  - 'financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.0'
  - flexcube_core_banking = 11.7.0
  - flexcube_core_banking = 11.8.0
  - flexcube_core_banking = 11.9.0
  - flexcube_core_banking = 11.10.0
  - fusion_middleware = 12.2.1.4.0
  - health_sciences_empirica_signal = 9.0
  - health_sciences_information_manager = 3.0.1
  - 'insurance_policy_administration_j2ee >= 11.1.0, <= 11.3.0'
  - insurance_policy_administration_j2ee = 10.2.0
  - insurance_policy_administration_j2ee = 10.2.4
  - insurance_policy_administration_j2ee = 11.0.2
  - 'insurance_rules_palette >= 11.1.0, <= 11.3.0'
  - insurance_rules_palette = 10.2.0
  - insurance_rules_palette = 10.2.4
  - insurance_rules_palette = 11.0.2
  - jdeveloper = 12.2.1.4.0
  - >-
    primavera_p6_enterprise_project_portfolio_management >= 16.1.0.0, <=
    16.2.20.1
  - >-
    primavera_p6_enterprise_project_portfolio_management >= 17.1.0.0, <=
    17.12.17.1
  - >-
    primavera_p6_enterprise_project_portfolio_management >= 18.1.0.0, <=
    18.8.19.0
  - >-
    primavera_p6_enterprise_project_portfolio_management >= 19.12.0.0, <=
    19.12.6.0
  - rapid_planning = 12.1
  - rapid_planning = 12.2
  - retail_customer_management_and_segmentation_foundation = 16.0
  - retail_customer_management_and_segmentation_foundation = 17.0
  - retail_customer_management_and_segmentation_foundation = 18.0
  - retail_customer_management_and_segmentation_foundation = 19.0
  - retail_integration_bus = 15.0
  - retail_integration_bus = 16.0
  - retail_order_broker = 15.0
  - retail_order_broker = 16.0
  - retail_order_broker = 18.0
  - retail_order_broker = 19.0
  - retail_order_broker = 19.1
  - retail_price_management = 14.0.3
  - retail_price_management = 14.1.3.0
  - retail_price_management = 15.0.3.0
  - retail_price_management = 16.0.3.0
  - retail_xstore_point_of_service = 15.0.4
  - retail_xstore_point_of_service = 16.0.6
  - retail_xstore_point_of_service = 17.0.4
  - retail_xstore_point_of_service = 18.0.3
  - storagetek_tape_analytics_sw_tool = 2.3
  - 'utilities_framework >= 4.3.0.1.0, <= 4.3.0.6.0'
  - utilities_framework = 2.2.0.0.0
  - utilities_framework = 4.2.0.2.0
  - utilities_framework = 4.2.0.3.0
  - utilities_framework = 4.4.0.0.0
  - utilities_framework = 4.4.0.2.0
  - webcenter_portal = 11.1.1.9.0
  - webcenter_portal = 12.2.1.3.0
  - webcenter_portal = 12.2.1.4.0
  - leap = 15.1
  - oncommand_api_services
  - oncommand_workflow_automation
  - snap_creator_framework
  - snapcenter
  - snapmanager
  - ubuntu_linux = 16.04
patched:
  - dom4j 2.1.3
published: '2020-05-01'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-10683'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html'
    label: cve@mitre.org
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1694235'
    label: cve@mitre.org
  - url: >-
      https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
    label: cve@mitre.org
  - url: >-
      https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658
    label: cve@mitre.org
  - url: 'https://github.com/dom4j/dom4j/commits/version-2.0.3'
    label: cve@mitre.org
  - url: 'https://github.com/dom4j/dom4j/issues/87'
    label: cve@mitre.org
  - url: 'https://github.com/dom4j/dom4j/releases/tag/version-2.1.3'
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20200518-0002/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4575-1/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1694235'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/dom4j/dom4j/commits/version-2.0.3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/dom4j/dom4j/issues/87'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/dom4j/dom4j/releases/tag/version-2.1.3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20200518-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4575-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.07269
epssPercentile: 0.94157
ingestedAt: '2026-08-25T17:29:29.946Z'
---

## Overview

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

## Affected

- `dom4j < 2.0.3`
- `dom4j >= 2.1.0, < 2.1.3`
- `agile_product_lifecycle_management = 9.3.3`
- `agile_product_lifecycle_management = 9.3.5`
- `application_testing_suite = 13.3.0.1`
- `banking_platform >= 2.4.0, <= 2.10.0`
- `business_process_management_suite = 12.2.1.3.0`
- `business_process_management_suite = 12.2.1.4.0`
- `communications_application_session_controller = 3.9m0p1`
- `communications_diameter_signaling_router >= 8.0.0, <= 8.2.2`
- `communications_unified_inventory_management = 7.3.0`
- `communications_unified_inventory_management = 7.4.0`
- `data_integrator = 12.2.1.3.0`
- `data_integrator = 12.2.1.4.0`
- `documaker >= 12.6.0, <= 12.6.4`
- `endeca_information_discovery_integrator = 3.2.0`
- `enterprise_data_quality = 11.1.1.9.0`
- `enterprise_data_quality = 12.2.1.3.0`
- `enterprise_manager_base_platform = 13.4.0.0`
- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.0`
- `flexcube_core_banking = 11.7.0`
- `flexcube_core_banking = 11.8.0`
- `flexcube_core_banking = 11.9.0`
- `flexcube_core_banking = 11.10.0`
- `fusion_middleware = 12.2.1.4.0`
- `health_sciences_empirica_signal = 9.0`
- `health_sciences_information_manager = 3.0.1`
- `insurance_policy_administration_j2ee >= 11.1.0, <= 11.3.0`
- `insurance_policy_administration_j2ee = 10.2.0`
- `insurance_policy_administration_j2ee = 10.2.4`
- `insurance_policy_administration_j2ee = 11.0.2`
- `insurance_rules_palette >= 11.1.0, <= 11.3.0`
- `insurance_rules_palette = 10.2.0`
- `insurance_rules_palette = 10.2.4`
- `insurance_rules_palette = 11.0.2`
- `jdeveloper = 12.2.1.4.0`
- `primavera_p6_enterprise_project_portfolio_management >= 16.1.0.0, <= 16.2.20.1`
- `primavera_p6_enterprise_project_portfolio_management >= 17.1.0.0, <= 17.12.17.1`
- `primavera_p6_enterprise_project_portfolio_management >= 18.1.0.0, <= 18.8.19.0`
- `primavera_p6_enterprise_project_portfolio_management >= 19.12.0.0, <= 19.12.6.0`
- `rapid_planning = 12.1`
- `rapid_planning = 12.2`
- `retail_customer_management_and_segmentation_foundation = 16.0`
- `retail_customer_management_and_segmentation_foundation = 17.0`
- `retail_customer_management_and_segmentation_foundation = 18.0`
- `retail_customer_management_and_segmentation_foundation = 19.0`
- `retail_integration_bus = 15.0`
- `retail_integration_bus = 16.0`
- `retail_order_broker = 15.0`
- `retail_order_broker = 16.0`
- `retail_order_broker = 18.0`
- `retail_order_broker = 19.0`
- `retail_order_broker = 19.1`
- `retail_price_management = 14.0.3`
- `retail_price_management = 14.1.3.0`
- `retail_price_management = 15.0.3.0`
- `retail_price_management = 16.0.3.0`
- `retail_xstore_point_of_service = 15.0.4`
- `retail_xstore_point_of_service = 16.0.6`
- `retail_xstore_point_of_service = 17.0.4`
- `retail_xstore_point_of_service = 18.0.3`
- `storagetek_tape_analytics_sw_tool = 2.3`
- `utilities_framework >= 4.3.0.1.0, <= 4.3.0.6.0`
- `utilities_framework = 2.2.0.0.0`
- `utilities_framework = 4.2.0.2.0`
- `utilities_framework = 4.2.0.3.0`
- `utilities_framework = 4.4.0.0.0`
- `utilities_framework = 4.4.0.2.0`
- `webcenter_portal = 11.1.1.9.0`
- `webcenter_portal = 12.2.1.3.0`
- `webcenter_portal = 12.2.1.4.0`
- `leap = 15.1`
- `oncommand_api_services`
- `oncommand_workflow_automation`
- `snap_creator_framework`
- `snapcenter`
- `snapmanager`
- `ubuntu_linux = 16.04`

## Remediation

Upgrade past the affected range:

- `dom4j 2.1.3`
