CVE-2020-6958 Information

Description

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14 as used in NSA Ghidra and other products allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Reference

https://github.com/NationalSecurityAgency/ghidra/issues/943 https://github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE20in20YAJSWE28099s20JnlpSupport20affects20Ghidra20Server.md https://sourceforge.net/p/yajsw/bugs/166/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

HIGH

Base Severity

9.1

Share on: