CVE-2020-25257: XEE
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks for read/write access to arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25257?
CVE-2020-25257 has a severity level of medium due to its exploitation potential through XXE attacks.
How do I fix CVE-2020-25257?
To fix CVE-2020-25257, upgrade Hyland OnBase to a version above 20.3.10.1000, 19.8.16.1001, 18.0.0.38, 17.0.2.110, or 16.0.2.84.
What are the potential impacts of CVE-2020-25257?
The potential impacts of CVE-2020-25257 include unauthorized read/write access to arbitrary files on the server.
Which versions of Hyland OnBase are affected by CVE-2020-25257?
CVE-2020-25257 affects Hyland OnBase versions 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below, and 20.3.10.1000 and below.
What is an XXE attack in relation to CVE-2020-25257?
An XXE attack in relation to CVE-2020-25257 exploits improper processing of XML input to gain unauthorized access to files on the server.