CVE-2019-13990
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Affected (180)
Products: Softwareag: Quartz · Oracle: Apache Batik Mapviewer, Banking Enterprise Originations, Banking Enterprise Product Manufacturing, Banking Payments, Communications Ip Service Activator, Communications Session Route Manager, Customer Management And Segmentation Foundation, Documaker, Enterprise Manager Base Platform, Enterprise Manager Ops Center, Flexcube Investor Servicing, Flexcube Private Banking, Fusion Middleware Mapviewer, Google Guava Mapviewer, Hyperion Infrastructure Technology, Jd Edwards Enterpriseone Orchestrator, Primavera Unifier, Retail Back Office, Retail Central Office, Retail Integration Bus, Retail Order Broker, Retail Point Of Service, Retail Returns Management, Retail Xstore Point Of Service, Terracotta Quartz Scheduler Mapviewer, Webcenter Sites · Apache: Tomee · +2 more
Show all products
Softwareag: Quartz · Oracle: Apache Batik Mapviewer, Banking Enterprise Originations, Banking Enterprise Product Manufacturing, Banking Payments, Communications Ip Service Activator, Communications Session Route Manager, Customer Management And Segmentation Foundation, Documaker, Enterprise Manager Base Platform, Enterprise Manager Ops Center, Flexcube Investor Servicing, Flexcube Private Banking, Fusion Middleware Mapviewer, Google Guava Mapviewer, Hyperion Infrastructure Technology, Jd Edwards Enterpriseone Orchestrator, Primavera Unifier, Retail Back Office, Retail Central Office, Retail Integration Bus, Retail Order Broker, Retail Point Of Service, Retail Returns Management, Retail Xstore Point Of Service, Terracotta Quartz Scheduler Mapviewer, Webcenter Sites · Apache: Tomee · Netapp: Active Iq Unified Manager, Cloud Secure Agent · Atlassian: Jira Service Management
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.2.0.1 | |
| Version 2.7.0 | |
| Version 2.7.0 | |
| From 14.1.0 to 14.4.0 | |
| Version 7.3.0 | |
| From 8.2.0 to 8.2.2 | |
| Version 18.0 | |
| From 12.6.0 to 12.6.4 | |
| Version 13.2.1.0 | |
| Version 12.4.0.0 | |
| Version 12.1.0 | |
| Version 12.0.0 | |
| Version 12.2.1.3.0 | |
| Version 12.2.0.1 | |
| Version 11.1.2.4 | |
| Up to 9.2.5.3 | |
| From 17.7 to 17.12 | |
| Version 14.1 | |
| Version 14.1 | |
| Version 15.0 | |
| Version 15.0 | |
| Version 14.1 | |
| Version 14.1 | |
| Version 15.0 | |
| Version 12.2.0.1 | |
| Version 12.2.1.3.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.20.0 |
References (34)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.