CVE-2020-25020: XEE
Published Aug 29, 2020
·Updated
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
Affected Software
7 affected components
MPXJ MPXJ<=8.1.3
Oracle Primavera Unifier>=17.7<=17.12
Oracle Primavera Unifier=16.1
Oracle Primavera Unifier=16.2
Oracle Primavera Unifier=18.8
Oracle Primavera Unifier=19.12
Oracle Primavera Unifier=20.12
Remediation
Patch Available
Event History
Aug 29, 2020
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-25020.
2
What is the severity of CVE-2020-25020?
The severity of CVE-2020-25020 is critical with a CVSS score of 9.8.
3
Which components are affected by CVE-2020-25020?
The GanttProjectReader and PhoenixReader components in MPXJ up to version 8.1.3 are affected by CVE-2020-25020.
4
How does CVE-2020-25020 allow XXE attacks?
CVE-2020-25020 allows XXE attacks due to insufficient XML input validation in the affected components.
5
What is the recommended fix for CVE-2020-25020?
To fix CVE-2020-25020, update MPXJ to a version beyond 8.1.3 or apply the necessary patches provided by the vendor.