Home / Companies / Dynatrace / Blog / Post Details
Content Deep Dive

Why the supposedly fixed CVE-2020-36641 vulnerability is still exploitable—And what to do about it

Blog post from Dynatrace

Post Details
Company
Date Published
Author
Stefan Achleitner, Jasper Juergensen
Word Count
1,017
Company Posts That Month
21
Language
American English
Hacker News Points
-
Post removed?
No
Summary

CVE-2020-36641 is a critical vulnerability in the Java library aXMLRPC, which allows XML-RPC protocol communications over HTTP and was initially believed to be fixed in versions 1.12.1 and higher. However, Dynatrace security researchers discovered that these versions were still susceptible to XML external entity (XXE) attacks, allowing attackers to perform various exploits. After discussions with the developers, aXMLRPC version 1.14.0 was released, effectively addressing the vulnerability. Despite previous claims of resolution from multiple sources, including the National Vulnerability Database and GitHub Security Advisories, the vulnerability remained due to a reversion of initial fixes aimed at solving related issues. This oversight highlights challenges in maintaining accurate vulnerability tracking, which can lead to significant cybersecurity threats or resource allocation issues. Dynatrace ensures its customers are protected by integrating accurate security findings into its platform, emphasizing the importance of reliable threat intelligence in cybersecurity.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.