CVE-2020-14338
Estado: ModificadaMedia (5.3)—
Se encontró un fallo en la implementación de Xerces de Wildfly, específicamente en la manera en que la clase XMLSchemaValidator en el componente JAXP de Wildfly aplicó la característica "use-grammar-pool-only". Este fallo permite a un archivo XML especialmente diseñado manipular el proceso de comprobación en determinados casos. Este problema es el mismo fallo que CVE-2020-14621, que afectó a OpenJDK, y usa un código similar. Todas las versiones de xerces jboss anteriores a 2.12.0.SP3
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.29%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 10/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
- CWE-20
Referencias
- https://bugzilla.redhat.com/show_bug.cgi?id=1860054
- https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E
- https://bugzilla.redhat.com/show_bug.cgi?id=1860054
- https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-14338",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Wildfly",
"versions": [
{
"status": "affected",
"version": "All xerces jboss versions before 2.12.0.SP3"
}
]
}
]
}
],
"published": "2020-09-17T15:15:13.143",
"references": [
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860054",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860054",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the \"use-grammar-pool-only\" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3."
},
{
"lang": "es",
"value": "Se encontró un fallo en la implementación de Xerces de Wildfly, específicamente en la manera en que la clase XMLSchemaValidator en el componente JAXP de Wildfly aplicó la característica \"use-grammar-pool-only\". Este fallo permite a un archivo XML especialmente diseñado manipular el proceso de comprobación en determinados casos. Este problema es el mismo fallo que CVE-2020-14621, que afectó a OpenJDK, y usa un código similar. Todas las versiones de xerces jboss anteriores a 2.12.0.SP3"
}
],
"lastModified": "2026-06-17T02:54:33.890",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:xerces:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D2BDDBB-28F6-45AB-A8FE-64344E4652F8",
"versionEndExcluding": "2.12.0"
},
{
"criteria": "cpe:2.3:a:redhat:xerces:2.12.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90F893C6-5CD7-48D0-9BC9-375D80D23879"
},
{
"criteria": "cpe:2.3:a:redhat:xerces:2.12.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1E5C0FEC-49FD-46DD-A529-BB49EA86CFF2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}