Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-13990

Опубликовано: 26 июл. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:softwareag:quartz:*:*:*:*:*:*:*:*
Версия до 2.3.2 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:oracle:apache_batik_mapviewer:12.2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:apache_batik_mapviewer:18c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:apache_batik_mapviewer:19c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_enterprise_originations:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_enterprise_originations:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_enterprise_product_manufacturing:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_enterprise_product_manufacturing:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_payments:*:*:*:*:*:*:*:*
Версия от 14.1.0 (включая) до 14.4.0 (включая)
cpe:2.3:a:oracle:communications_ip_service_activator:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_ip_service_activator:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*
Версия от 8.2.0 (включая) до 8.2.2 (включая)
cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:documaker:*:*:*:*:*:*:*:*
Версия от 12.6.0 (включая) до 12.6.4 (включая)
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_investor_servicing:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_investor_servicing:12.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_investor_servicing:12.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_investor_servicing:14.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_investor_servicing:14.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:google_guava_mapviewer:12.2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:google_guava_mapviewer:18c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:google_guava_mapviewer:19c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:*:*:*:*:*:*:*:*
Версия до 9.2.5.3 (включая)
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
Версия от 17.7 (включая) до 17.12 (включая)
cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_central_office:14.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_order_broker:18.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_order_broker:19.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:terracotta_quartz_scheduler_mapviewer:12.2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:terracotta_quartz_scheduler_mapviewer:18c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:terracotta_quartz_scheduler_mapviewer:19c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:apache:tomee:7.1.3:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:*
Конфигурация 5

Одно из

cpe:2.3:a:atlassian:jira_service_management:4.20.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.2:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.2:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.3:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.3:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.4:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.4:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.5:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.5:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.6:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.6:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.7:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.7:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.8:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.8:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.9:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.9:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.10:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.10:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.11:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.11:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.12:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.12:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.13:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.13:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.14:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.14:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.15:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.15:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.16:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.16:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.17:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.17:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.18:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.18:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.19:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.19:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.20:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.20:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.21:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.21:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.22:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.22:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.23:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.23:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.24:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.24:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.25:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.20.25:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.21.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.21.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.21.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.21.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.2:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.2:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.3:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.3:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.4:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.4:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.6:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:4.22.6:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.0.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.0.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.1.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.1.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.1.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.1.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.2.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.2.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.2.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.2.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.3.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.3.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.3.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.3.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.3.2:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.3.2:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.3.3:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.3.3:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.2:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.2:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.3:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.3:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.4:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.4:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.5:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.5:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.6:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.6:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.7:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.7:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.8:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.8:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.9:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.4.9:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.5.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.5.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.6.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.6.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.7.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.7.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.7.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.7.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.8.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.8.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.8.1:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.8.1:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.9.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.9.0:*:*:*:server:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.10.0:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:5.10.0:*:*:*:server:*:*:*

EPSS

Процентиль: 92%
0.08578
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

CVSS3: 8.1
redhat
больше 6 лет назад

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

CVSS3: 9.8
debian
больше 6 лет назад

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracott ...

CVSS3: 9.8
github
больше 5 лет назад

XML external entity injection in Terracotta Quartz Scheduler

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость функции initDocumentParser библиотеки планирования заданий Terracotta Quartz Scheduler, позволяющая нарушителю осуществить XXE-атаку

EPSS

Процентиль: 92%
0.08578
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-611
CWE-611