Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9628

Опубликовано: 11 мар. 2019
Источник: redhat
CVSS3: 7.5

Описание

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6xmltoolingOut of support scope
Red Hat JBoss Data Virtualization 6xmltoolingOut of support scope
Red Hat JBoss Enterprise Application Platform 6xmltoolingOut of support scope
Red Hat JBoss Fuse 6xmltoolingOut of support scope
Red Hat JBoss Fuse Service Works 6xmltoolingOut of support scope
Red Hat JBoss Operations Network 3XMLToolingOut of support scope
Red Hat JBoss Portal 6xmltoolingOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1695997xmltooling: XML parser class fails to trap exceptions on malformed XML declaration

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.

CVSS3: 7.5
nvd
больше 7 лет назад

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.

CVSS3: 7.5
debian
больше 7 лет назад

The XMLTooling library all versions prior to V3.0.4, provided with the ...

suse-cvrf
больше 7 лет назад

Security update for xmltooling

suse-cvrf
больше 7 лет назад

Security update for xmltooling

7.5 High

CVSS3