CVE-2019-5427
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Affected (19)
Products: Mchange: C3p0 · Fedoraproject: Fedora · Oracle: Communications Ip Service Activator, Communications Session Route Manager, Documaker, Enterprise Manager Base Platform, Enterprise Manager Ops Center, Flexcube Private Banking, Hyperion Infrastructure Technology, Retail Xstore Point Of Service, Webcenter Sites
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 29 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.3.0 | |
| From 8.2.0 to 8.2.2 | |
| From 12.6.0 to 12.6.6 | |
| Version 13.2.1.0 | |
| Version 12.4.0.0 | |
| Version 12.0.0 | |
| Version 11.1.2.4 | |
| Version 15.0 | |
| Version 12.2.1.3.0 |
References (16)
Source: support@hackerone.com
ExploitIssue TrackingPatchThird Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.