CVE-2020-10683: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 7.3% chance of exploitation in the next 30 days.

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only
  • DOM4J Project DOM4J: before 2.0.3 (fixed in 2.0.3); from 2.1.0, before 2.1.3 (fixed in 2.1.3)
  • Netapp Oncommand API Services: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Snap Creator Framework: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Snapmanager: affected versions not specified
  • Opensuse Leap: version 15.1 only
  • Oracle Agile Product Lifecycle Management: version 9.3.3 only; version 9.3.5 only
  • Oracle Application Testing Suite: version 13.3.0.1 only
  • Oracle Banking Platform: from 2.4.0, up to and including 2.10.0
  • Oracle Business Process Management Suite: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Communications Application Session Controller: version 3.9m0p1 only
  • Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
  • Oracle Communications Unified Inventory Management: version 7.3.0 only; version 7.4.0 only
  • Oracle Data Integrator: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Documaker: from 12.6.0, up to and including 12.6.4
  • Oracle Endeca Information Discovery Integrator: version 3.2.0 only
  • Oracle Enterprise Data Quality: version 11.1.1.9.0 only; version 12.2.1.3.0 only
  • Oracle Enterprise Manager Base Platform: version 13.4.0.0 only
  • Oracle Financial Services Analytical Applications Infrastructure: from 8.0.6, up to and including 8.1.0
  • Oracle Flexcube Core Banking: version 11.7.0 only; version 11.8.0 only; version 11.9.0 only; version 11.10.0 only
  • Oracle Fusion Middleware: version 12.2.1.4.0 only
  • Oracle Health Sciences Empirica Signal: version 9.0 only
  • Oracle Health Sciences Information Manager: version 3.0.1 only
  • and 13 more

Published 2020-05-01. Last modified 2026-08-25.