PoC Index

CVE-2020-6958

CRITICAL 9.1EPSS 2.4%

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.

CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS v2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
EPSS
2.35% chance of exploitation in the next 30 days, 83th percentile
Published
2020-01-13
Updated
2024-08-04

Proof-of-concept exploits (3)

References

Related