PT-2020-3788 · Oracle+2 · Jaxp+3

Chess Hazlett

·

Published

2020-08-27

·

Updated

2022-02-15

·

CVE-2020-14338

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: WildFly versions prior to 2.12.0.SP3 Xerces JBoss versions prior to 2.12.0.SP3
Description: The issue is related to insufficient input validation in the XMLSchemaValidator class of the JAXP component in WildFly. This allows a remote attacker to manipulate the validation process using a specially crafted XML file, potentially leading to unauthorized access to data. The flaw is similar to one found in OpenJDK and affects the "use-grammar-pool-only" feature.
Recommendations: For WildFly versions prior to 2.12.0.SP3, update to version 2.12.0.SP3 or later to resolve the issue. For Xerces JBoss versions prior to 2.12.0.SP3, update to version 2.12.0.SP3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the XMLSchemaValidator class in the JAXP component until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04150
CVE-2020-14338
GHSA-W4JQ-QH47-HVJQ
RHSA-2020:4244
RHSA-2020:4245
RHSA-2020:4246

Affected Products

Jaxp
Openjdk
Wildfly
Xerces