VYPR
Medium severity5.3NVD Advisory· Published Dec 14, 2020· Updated Jun 17, 2026

CVE-2020-35460

CVE-2020-35460

Description

common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
net.sf.mpxj:mpxjMaven
< 8.3.58.3.5

Affected products

9
  • cpe:2.3:a:mpxj:mpxj:*:*:*:*:*:*:*:*
    Range: <8.3.5
  • cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*range: >=17.7,<=17.12
    • cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*
  • Packwood/MPXJdescription
  • ghsa-coords
    Range: < 8.3.5

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.