5
CVSSv2

CVE-2020-14338

Published: 17/09/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions prior to 2.12.0.SP3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat xerces 2.12.0

redhat xerces

Vendor Advisories

Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 733 security update on RHEL 8 Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 73 for RHEL 8Red Hat Product Security has rated this update as having a security imp ...
Synopsis Important: Red Hat Process Automation Manager 7100 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
Synopsis Moderate: Red Hat Single Sign-On 743 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 74 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 733 security update on RHEL 7 Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 73 for RHEL 7Red Hat Product Security has rated this update as having a security imp ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 733 security update on RHEL 6 Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 73 for RHEL 6Red Hat Product Security has rated this update as having a security imp ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 733 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 73Red Hat Product Security has rated this update as having a security impact of Moderate A Co ...
Synopsis Important: Red Hat Decision Manager 7100 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Decision ManagerRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Important: Red Hat build of Thorntail 272 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of ThorntailRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...