Medium severity5.3NVD Advisory· Published Dec 14, 2020· Updated Jun 17, 2026
CVE-2020-35460
CVE-2020-35460
Description
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.sf.mpxj:mpxjMaven | < 8.3.5 | 8.3.5 |
Affected products
9cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*range: >=17.7,<=17.12
- cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*
- Packwood/MPXJdescription
Patches
Vulnerability mechanics
References
5- github.com/joniles/mpxj/commit/8eaf4225048ea5ba7e59ef4556dab2098fcc4a1dnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2021.htmlnvdPatchThird Party AdvisoryWEB
- www.mpxj.org/changes-report.htmlnvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-p9j6-4pjr-gp48ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-35460ghsaADVISORY
News mentions
0No linked articles in our index yet.