Critical severity9.1NVD Advisory· Published Jan 14, 2020· Updated Jun 17, 2026
CVE-2020-6958
CVE-2020-6958
Description
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:yet_another_java_service_wrapper_project:yet_another_java_service_wrapper:12.14:*:*:*:*:*:*:*
- Yet Another Java Service Wrapper/Yet Another Java Service Wrapperdescription
- Range: <12.14
Patches
Vulnerability mechanics
References
3- github.com/NationalSecurityAgency/ghidra/issues/943nvdExploitThird Party Advisory
- sourceforge.net/p/yajsw/bugs/166/nvdExploitThird Party Advisory
- github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%E2%80%99s%20JnlpSupport%20affects%20Ghidra%20Server.mdnvdThird Party Advisory
News mentions
0No linked articles in our index yet.