Description
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Canonical / Ubuntu Linux16.04 – 16.04
- dom4j_project / dom4j2.0.3
- NETAPP / oncommand_api_services
- NETAPP / OnCommand Workflow Automation
- NETAPP / SnapCenter
- NETAPP / snap_creator_framework
- NETAPP / snapmanager
- NETAPP / snapmanager
- openSUSE / Leap15.1 – 15.1
- oracle / agile_product_lifecycle_management9.3.3 – 9.3.3
- oracle / agile_product_lifecycle_management9.3.5 – 9.3.5
- oracle / Application Testing Suite13.3.0.1 – 13.3.0.1
- oracle / banking_platform2.4.0 – 2.10.0
- oracle / business_process_management_suite12.2.1.3.0 – 12.2.1.3.0
- oracle / business_process_management_suite12.2.1.4.0 – 12.2.1.4.0
- oracle / communications_application_session_controller3.9m0p1 – 3.9m0p1
- oracle / communications_diameter_signaling_router8.0.0 – 8.2.2
- oracle / communications_unified_inventory_management7.3.0 – 7.3.0
- oracle / communications_unified_inventory_management7.4.0 – 7.4.0
- oracle / data_integrator12.2.1.4.0 – 12.2.1.4.0
- oracle / data_integrator12.2.1.3.0 – 12.2.1.3.0
- oracle / documaker12.6.0 – 12.6.4
- oracle / endeca_information_discovery_integrator3.2.0 – 3.2.0
- oracle / enterprise_data_quality11.1.1.9.0 – 11.1.1.9.0
- oracle / enterprise_data_quality12.2.1.3.0 – 12.2.1.3.0
- oracle / enterprise_manager_base_platform13.4.0.0 – 13.4.0.0
- oracle / financial_services_analytical_applications_infrastructure8.0.6 – 8.1.0
- oracle / FLEXCUBE Core Banking11.10.0 – 11.10.0
- oracle / FLEXCUBE Core Banking11.7.0 – 11.7.0
- oracle / FLEXCUBE Core Banking11.8.0 – 11.8.0
- oracle / FLEXCUBE Core Banking11.9.0 – 11.9.0
- oracle / fusion_middleware12.2.1.4.0 – 12.2.1.4.0
- oracle / health_sciences_empirica_signal9.0 – 9.0
- oracle / health_sciences_information_manager3.0.1 – 3.0.1
- oracle / insurance_policy_administration_j2ee11.1.0 – 11.3.0
- oracle / insurance_policy_administration_j2ee10.2.0 – 10.2.0
- oracle / insurance_policy_administration_j2ee11.0.2 – 11.0.2
- oracle / insurance_policy_administration_j2ee10.2.4 – 10.2.4
- oracle / insurance_rules_palette11.1.0 – 11.3.0
- oracle / insurance_rules_palette11.0.2 – 11.0.2
- oracle / insurance_rules_palette10.2.4 – 10.2.4
- oracle / insurance_rules_palette10.2.0 – 10.2.0
- oracle / JDeveloper12.2.1.4.0 – 12.2.1.4.0
- oracle / primavera_p6_enterprise_project_portfolio_management16.1.0.0 – 16.2.20.1
- oracle / rapid_planning12.2 – 12.2
- oracle / rapid_planning12.1 – 12.1
- oracle / retail_customer_management_and_segmentation_foundation19.0 – 19.0
- oracle / retail_customer_management_and_segmentation_foundation16.0 – 16.0
- oracle / retail_customer_management_and_segmentation_foundation17.0 – 17.0
- oracle / retail_customer_management_and_segmentation_foundation18.0 – 18.0
- oracle / retail_integration_bus15.0 – 15.0
- oracle / retail_integration_bus16.0 – 16.0
- oracle / retail_order_broker18.0 – 18.0
- oracle / retail_order_broker19.0 – 19.0
- oracle / retail_order_broker19.1 – 19.1
- oracle / retail_order_broker16.0 – 16.0
- oracle / retail_order_broker15.0 – 15.0
- oracle / retail_price_management14.0.3 – 14.0.3
- oracle / retail_price_management15.0.3.0 – 15.0.3.0
- oracle / retail_price_management16.0.3.0 – 16.0.3.0
- oracle / retail_price_management14.1.3.0 – 14.1.3.0
- oracle / retail_xstore_point_of_service16.0.6 – 16.0.6
- oracle / retail_xstore_point_of_service18.0.3 – 18.0.3
- oracle / retail_xstore_point_of_service17.0.4 – 17.0.4
- oracle / retail_xstore_point_of_service15.0.4 – 15.0.4
- oracle / storagetek_tape_analytics_sw_tool2.3 – 2.3
- oracle / utilities_framework4.3.0.1.0 – 4.3.0.6.0
- oracle / utilities_framework4.2.0.3.0 – 4.2.0.3.0
- oracle / utilities_framework4.2.0.2.0 – 4.2.0.2.0
- oracle / utilities_framework2.2.0.0.0 – 2.2.0.0.0
- oracle / utilities_framework4.4.0.2.0 – 4.4.0.2.0
- oracle / utilities_framework4.4.0.0.0 – 4.4.0.0.0
- oracle / webcenter_portal12.2.1.3.0 – 12.2.1.3.0
- oracle / webcenter_portal11.1.1.9.0 – 11.1.1.9.0
- oracle / webcenter_portal12.2.1.4.0 – 12.2.1.4.0
References
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujul2020.html
- MISChttps://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=1694235
- PATCHhttps://github.com/dom4j/dom4j/releases/tag/version-2.1.3
- PATCHhttps://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658
- MISChttps://security.netapp.com/advisory/ntap-20200518-0002/
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4575-1/
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpuoct2020.html
- MISChttps://github.com/dom4j/dom4j/issues/87
- MISChttps://github.com/dom4j/dom4j/commits/version-2.0.3
- MAILING_LISThttps://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujan2021.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpuApr2021.html
- VENDOR_ADVISORYhttps://www.oracle.com//security-alerts/cpujul2021.html
- MAILING_LISThttps://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpuoct2021.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujan2022.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujul2022.html
Updated 19m ago · 8 sources