PT-2020-3788 · Oracle+2 · Jaxp+3
Chess Hazlett
·
Published
2020-08-27
·
Updated
2022-02-15
·
CVE-2020-14338
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
WildFly versions prior to 2.12.0.SP3
Xerces JBoss versions prior to 2.12.0.SP3
Description:
The issue is related to insufficient input validation in the XMLSchemaValidator class of the JAXP component in WildFly. This allows a remote attacker to manipulate the validation process using a specially crafted XML file, potentially leading to unauthorized access to data. The flaw is similar to one found in OpenJDK and affects the "use-grammar-pool-only" feature.
Recommendations:
For WildFly versions prior to 2.12.0.SP3, update to version 2.12.0.SP3 or later to resolve the issue.
For Xerces JBoss versions prior to 2.12.0.SP3, update to version 2.12.0.SP3 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the XMLSchemaValidator class in the JAXP component until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jaxp
Openjdk
Wildfly
Xerces