AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-6856

MEDIUM · CVSS 6.5 EPSS 0.93%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-02-06 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. See the original NVD description below for full technical details.

CVE
CVE-2020-6856
Severity
MEDIUM
CVSS
6.5
EPSS
0.93%

Original NVD Description

An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specify the run-time settings of jobs and orders.

Related CVEs

Other vulnerabilities affecting the same vendor(s)