570
VMScore

CVE-2020-6958

Published: 14/01/2020 Updated: 21/01/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows malicious users to exfiltrate data from remote hosts and potentially cause denial-of-service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yet another java service wrapper project yet another java service wrapper 12.14