← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-13990

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:16.63%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-611 ↗CWE-611 Improper Restriction of XML External Entity Reference

Affected Products & Versions

Vendor Product Affected Versions
softwareag quartz all
oracle apache_batik_mapviewer 12.2.0.1, 18c, 19c
oracle banking_enterprise_originations 2.7.0, 2.8.0
oracle banking_enterprise_product_manufacturing 2.7.0, 2.8.0
oracle banking_payments all
oracle communications_ip_service_activator 7.3.0, 7.4.0
oracle communications_session_route_manager all
oracle customer_management_and_segmentation_foundation 18.0
oracle documaker all
oracle enterprise_manager_base_platform 13.2.1.0
oracle enterprise_manager_ops_center 12.4.0.0
oracle flexcube_investor_servicing 12.1.0, 12.3.0, 12.4.0, 14.1.0, 14.4.0
oracle flexcube_private_banking 12.0.0, 12.1.0
oracle fusion_middleware_mapviewer 12.2.1.3.0
oracle google_guava_mapviewer 12.2.0.1, 18c, 19c
oracle hyperion_infrastructure_technology 11.1.2.4
oracle jd_edwards_enterpriseone_orchestrator all
oracle primavera_unifier 16.1, 16.2, 18.8
oracle retail_back_office 14.1
oracle retail_central_office 14.1
oracle retail_integration_bus 15.0, 16.0
oracle retail_order_broker 15.0, 16.0, 18.0, 19.0
oracle retail_point-of-service 14.1
oracle retail_returns_management 14.1
oracle retail_xstore_point_of_service 15.0, 16.0, 17.0, 18.0, 19.0
oracle terracotta_quartz_scheduler_mapviewer 12.2.0.1, 18c, 19c
oracle webcenter_sites 12.2.1.3.0, 12.2.1.4.0
apache tomee 7.1.3
netapp active_iq_unified_manager all
netapp cloud_secure_agent all
atlassian jira_service_management 4.20.0, 4.20.1, 4.20.2, 4.20.3, 4.20.4, 4.20.5, 4.20.6, 4.20.7, 4.20.8, 4.20.9, 4.20.10, 4.20.11, 4.20.12, 4.20.13, 4.20.14, 4.20.15, 4.20.16, 4.20.17, 4.20.18, 4.20.19, 4.20.20, 4.20.21, 4.20.22, 4.20.23, 4.20.24, 4.20.25, 4.21.0, 4.21.1, 4.22.0, 4.22.1, 4.22.2, 4.22.3, 4.22.4, 4.22.6, 5.0.0, 5.1.0, 5.1.1, 5.2.0, 5.2.1, 5.3.0, 5.3.1, 5.3.2, 5.3.3, 5.4.0, 5.4.1, 5.4.2, 5.4.3, 5.4.4, 5.4.5, 5.4.6, 5.4.7, 5.4.8, 5.4.9, 5.5.1, 5.6.0, 5.7.0, 5.7.1, 5.8.0, 5.8.1, 5.9.0, 5.10.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
16.628%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-07-19T00:00:00
Published2019-07-26T00:00:00
Last Updated2024-10-15T18:22:20

LINK COPIED TO CLIPBOARD