CVE-2020-35460: Mpxj

Medium severity, CVSS 5.3. EPSS: 1.9% chance of exploitation in the next 30 days.

common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.

Affected products

  • Mpxj Mpxj: before 8.3.5 (fixed in 8.3.5)
  • Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only; version 19.12 only; version 21.12 only

Published 2020-12-14. Last modified 2026-06-17.