Input validation error in xerces - CVE-2020-14338
Published: February 27, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. A remote attacker can pass specially-crafted XML file to the application and manipulate the validation process in certain cases.
Affected software
Tivoli Network Manager IP Edition
IBM Engineering Requirements Management DOORS Next
IBM Engineering Systems Design Rhapsody
Call Center for Commerce
IBM Content Navigator
IBM SPSS Modeler
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Jazz Foundation
Jazz Reporting Service
How to mitigate CVE-2020-14338
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Jazz Foundation - update to 7.0.2.0.27
Jazz Reporting Service - addressed in versions 7.0.3 iFix009, 7.02 iFix031
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM Security Verify Governance - update to 10.0.2
Call Center for Commerce - update to 10.0.2403.1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Call Center for Commerce
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Jazz Foundation
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- IBM Jazz Reporting Service update for Wildfly
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition (ITNM)
- Multiple vulnerabilities in IBM Content Navigator
- Multiple vulnerabilities in IBM SPSS Modeler