Input validation error in xerces - CVE-2020-14338

 

Input validation error in xerces - CVE-2020-14338

Published: February 27, 2024


Vulnerability identifier: #VU86824
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14338
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. A remote attacker can pass specially-crafted XML file to the application and manipulate the validation process in certain cases.


Affected software

xerces
Tivoli Network Manager IP Edition
IBM Engineering Requirements Management DOORS Next
IBM Engineering Systems Design Rhapsody
Call Center for Commerce
IBM Content Navigator
IBM SPSS Modeler
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Jazz Foundation
Jazz Reporting Service

How to mitigate CVE-2020-14338

Install updates from vendor's website.

xerces - update to 2.12.0.SP3
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Jazz Foundation - update to 7.0.2.0.27
Jazz Reporting Service - addressed in versions 7.0.3 iFix009, 7.02 iFix031
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM Security Verify Governance - update to 10.0.2
Call Center for Commerce - update to 10.0.2403.1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6

External References

Related Security Bulletins