{"api_version":"1","generated_at":"2026-07-23T08:39:51+00:00","cve":"CVE-2020-6958","urls":{"html":"https://cve.report/CVE-2020-6958","api":"https://cve.report/api/cve/CVE-2020-6958.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-6958","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-6958"},"summary":{"title":"CVE-2020-6958","description":"An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-01-14 00:15:00","updated_at":"2020-01-21 16:08:00"},"problem_types":["CWE-611"],"metrics":[],"references":[{"url":"https://github.com/NationalSecurityAgency/ghidra/issues/943","name":"https://github.com/NationalSecurityAgency/ghidra/issues/943","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"XXE Vulnerability in JnlpSupport of YAJSW affects Ghidra Server · Issue #943 · NationalSecurityAgency/ghidra · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%E2%80%99s%20JnlpSupport%20affects%20Ghidra%20Server.md","name":"https://github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%E2%80%99s%20JnlpSupport%20affects%20Ghidra%20Server.md","refsource":"MISC","tags":["Third Party Advisory"],"title":"Exploits-and-PoC/XXE in YAJSW’s JnlpSupport affects Ghidra Server.md at master · purpleracc00n/Exploits-and-PoC · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://sourceforge.net/p/yajsw/bugs/166/","name":"https://sourceforge.net/p/yajsw/bugs/166/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Yet Another Java Service Wrapper / Bugs / #166 XXE Vulnerability in JnlpSupport of YAJSW","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-6958","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-6958","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"6958","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yet_another_java_service_wrapper_project","cpe5":"yet_another_java_service_wrapper","cpe6":"12.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"6958","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yet_another_java_service_wrapper_project","cpe5":"yet_another_java_service_wrapper","cpe6":"12.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-6958","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://sourceforge.net/p/yajsw/bugs/166/","refsource":"MISC","name":"https://sourceforge.net/p/yajsw/bugs/166/"},{"url":"https://github.com/NationalSecurityAgency/ghidra/issues/943","refsource":"MISC","name":"https://github.com/NationalSecurityAgency/ghidra/issues/943"},{"url":"https://github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%E2%80%99s%20JnlpSupport%20affects%20Ghidra%20Server.md","refsource":"MISC","name":"https://github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%E2%80%99s%20JnlpSupport%20affects%20Ghidra%20Server.md"}]}},"nvd":{"publishedDate":"2020-01-14 00:15:00","lastModifiedDate":"2020-01-21 16:08:00","problem_types":["CWE-611"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:yet_another_java_service_wrapper_project:yet_another_java_service_wrapper:12.14:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"6958","Ordinal":"167229","Title":"CVE-2020-6958","CVE":"CVE-2020-6958","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"6958","Ordinal":"1","NoteData":"An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"6958","Ordinal":"2","NoteData":"2020-01-13","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"6958","Ordinal":"3","NoteData":"2020-01-13","Type":"Other","Title":"Modified"}]}}}