Vulnerabilities > CVE-2020-6958 - XXE vulnerability in YET Another Java Service Wrapper Project YET Another Java Service Wrapper 12.14

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
yet-another-java-service-wrapper-project
CWE-611
critical

Summary

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.