CVE Feed

    Dashboard / CVE / CVE-2020-35460

    CVE-2020-35460

    common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.

    Published:Dec 14, 2020
    Last Modified:May 5, 2025
    EPS:Dec 14, 2020
    EPSS Score:0.00624
    CVSS Score:5.3

    Affected Products

    Vendor
    Mpxj
    Product
    Mpxj
    Vendor
    Oracle
    Product
    Primavera Unifier

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High