CVE-2019-13990

Aliases:GHSA-9qcf-c26r-x5rf
Modified
Published: 26 Jul 2019, 00:00
Last modified:15 Oct 2024, 18:22

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
13.78% MEDIUM
14% probability +5.20%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Jul 2019, 00:00
Published
Vulnerability first disclosed
15 Oct 2024, 18:22
Last Modified
Vulnerability information updated

Description

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 13.78% Percentile: 94%

Techniques & Countermeasures

  • CWE-611Improper Restriction of XML External Entity Reference

    The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Systems

  • apachetomee

    7.1.3

  • atlassianjira_service_management

    4.20.0 | 4.20.1 | 4.20.2 | 4.20.3 | 4.20.4 | 4.20.5 | 4.20.6 | 4.20.7 | 4.20.8 | 4.20.9 | 4.20.10 | 4.20.11 | 4.20.12 | 4.20.13 | 4.20.14 | 4.20.15 | 4.20.16 | 4.20.17 | 4.20.18 | 4.20.19 | 4.20.20 | 4.20.21 | 4.20.22 | 4.20.23 | 4.20.24 | 4.20.25 | 4.21.0 | 4.21.1 | 4.22.0 | 4.22.1 | 4.22.2 | 4.22.3 | 4.22.4 | 4.22.6 | 5.0.0 | 5.1.0 | 5.1.1 | 5.2.0 | 5.2.1 | 5.3.0 | 5.3.1 | 5.3.2 | 5.3.3 | 5.4.0 | 5.4.1 | 5.4.2 | 5.4.3 | 5.4.4 | 5.4.5 | 5.4.6 | 5.4.7 | 5.4.8 | 5.4.9 | 5.5.1 | 5.6.0 | 5.7.0 | 5.7.1 | 5.8.0 | 5.8.1 | 5.9.0 | 5.10.0

  • org.quartz-schedulerquartz

    < 2.3.2

  • netappactive_iq_unified_manager

    na

  • netappcloud_secure_agent

    na

  • oracleapache_batik_mapviewer

    12.2.0.1 | 18c | 19c

  • oraclebanking_enterprise_originations

    2.7.0 | 2.8.0

  • oraclebanking_enterprise_product_manufacturing

    2.7.0 | 2.8.0

  • oraclebanking_payments

    ≥ 14.1.0, ≤ 14.4.0

  • oraclecommunications_ip_service_activator

    7.3.0 | 7.4.0

  • oraclecommunications_session_route_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oraclecustomer_management_and_segmentation_foundation

    18.0

  • oracledocumaker

    ≥ 12.6.0, ≤ 12.6.4

  • oracleenterprise_manager_base_platform

    13.2.1.0

  • oracleenterprise_manager_ops_center

    12.4.0.0

  • oracleflexcube_investor_servicing

    12.1.0 | 12.3.0 | 12.4.0 | 14.1.0 | 14.4.0

  • oracleflexcube_private_banking

    12.0.0 | 12.1.0

  • oraclefusion_middleware_mapviewer

    12.2.1.3.0

  • oraclegoogle_guava_mapviewer

    12.2.0.1 | 18c | 19c

  • oraclehyperion_infrastructure_technology

    11.1.2.4

  • oraclejd_edwards_enterpriseone_orchestrator

    ≤ 9.2.5.3

  • oracleprimavera_unifier

    ≥ 17.7, ≤ 17.12 | 16.1 | 16.2 | 18.8

  • oracleretail_back_office

    14.1

  • oracleretail_central_office

    14.1

  • oracleretail_integration_bus

    15.0 | 16.0

  • oracleretail_order_broker

    15.0 | 16.0 | 18.0 | 19.0

  • oracleretail_point-of-service

    14.1

  • oracleretail_returns_management

    14.1

  • oracleretail_xstore_point_of_service

    15.0 | 16.0 | 17.0 | 18.0 | 19.0

  • oracleterracotta_quartz_scheduler_mapviewer

    12.2.0.1 | 18c | 19c

  • oraclewebcenter_sites

    12.2.1.3.0 | 12.2.1.4.0

  • softwareagquartz

    < 2.3.2

References (31)