CVE-2020-14621: Input Validation
A flaw was found in the way the XMLSchemaValidator class in the JAXP component of OpenJDK enforced the "use-grammar-pool-only" feature. A specially-crafted XML file could possibly use this flaw to manipulate with the validation process in certain cases.
Other sources
An unspecified vulnerability in Java SE related to the JAXP component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
— IBM
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-14621?
CVE-2020-14621 is an unspecified vulnerability in Java SE related to the JAXP component.
What versions of Java SE are affected by CVE-2020-14621?
Java SE versions 7u261, 8u251, 11.0.7, and 14.0.1 are affected by CVE-2020-14621.
How severe is CVE-2020-14621?
CVE-2020-14621 has a severity level of 5.3 (medium).
Is CVE-2020-14621 easily exploitable?
Yes, CVE-2020-14621 is an easily exploitable vulnerability.
How can I fix CVE-2020-14621?
To fix CVE-2020-14621, you should update to the patched versions of Java SE or Java SE Embedded provided by Oracle.