CVE-2020-25649 | Oracle Primavera Gateway up to 17.12.11/18.8.11/19.12.10/20.12.0 jackson-databind xml external entity reference
A vulnerability, which was classified as critical, was found in Oracle Primavera Gateway up to 17.12.11/18.8.11/19.12.10/20.12.0. The affected element is an unknown function of the component jackson-databind. Executing a manipulation can lead to xml external entity reference.
This vulnerability is registered as CVE-2020-25649. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.