9.8

CVE-2019-13990

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Data is provided by the National Vulnerability Database (NVD)
SoftwareagQuartz Version < 2.3.2
OracleApache Batik Mapviewer Version12.2.0.1
OracleBanking Payments Version >= 14.1.0 <= 14.4.0
OracleCommunications Session Route Manager Version >= 8.2.0 <= 8.2.2
OracleDocumaker Version >= 12.6.0 <= 12.6.4
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleFusion Middleware Mapviewer Version12.2.1.3.0
OracleGoogle Guava Mapviewer Version12.2.0.1
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OracleRetail Back Office Version14.1
OracleRetail Central Office Version14.1
OracleRetail Integration Bus Version15.0
OracleRetail Integration Bus Version16.0
OracleRetail Order Broker Version15.0
OracleRetail Order Broker Version16.0
OracleRetail Order Broker Version18.0
OracleRetail Order Broker Version19.0
OracleWebcenter Sites Version12.2.1.3.0
OracleWebcenter Sites Version12.2.1.4.0
ApacheTomee Version7.1.3
NetappActive Iq Unified Manager Version- SwPlatformlinux
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappActive Iq Unified Manager Version- SwPlatformwindows
NetappCloud Secure Agent Version-
AtlassianJira Service Management Version4.20.0 SwEditiondata_center
AtlassianJira Service Management Version4.20.0 SwEditionserver
AtlassianJira Service Management Version4.20.1 SwEditiondata_center
AtlassianJira Service Management Version4.20.1 SwEditionserver
AtlassianJira Service Management Version4.20.2 SwEditiondata_center
AtlassianJira Service Management Version4.20.2 SwEditionserver
AtlassianJira Service Management Version4.20.3 SwEditiondata_center
AtlassianJira Service Management Version4.20.3 SwEditionserver
AtlassianJira Service Management Version4.20.4 SwEditiondata_center
AtlassianJira Service Management Version4.20.4 SwEditionserver
AtlassianJira Service Management Version4.20.5 SwEditiondata_center
AtlassianJira Service Management Version4.20.5 SwEditionserver
AtlassianJira Service Management Version4.20.6 SwEditiondata_center
AtlassianJira Service Management Version4.20.6 SwEditionserver
AtlassianJira Service Management Version4.20.7 SwEditiondata_center
AtlassianJira Service Management Version4.20.7 SwEditionserver
AtlassianJira Service Management Version4.20.8 SwEditiondata_center
AtlassianJira Service Management Version4.20.8 SwEditionserver
AtlassianJira Service Management Version4.20.9 SwEditiondata_center
AtlassianJira Service Management Version4.20.9 SwEditionserver
AtlassianJira Service Management Version4.20.10 SwEditiondata_center
AtlassianJira Service Management Version4.20.10 SwEditionserver
AtlassianJira Service Management Version4.20.11 SwEditiondata_center
AtlassianJira Service Management Version4.20.11 SwEditionserver
AtlassianJira Service Management Version4.20.12 SwEditiondata_center
AtlassianJira Service Management Version4.20.12 SwEditionserver
AtlassianJira Service Management Version4.20.13 SwEditiondata_center
AtlassianJira Service Management Version4.20.13 SwEditionserver
AtlassianJira Service Management Version4.20.14 SwEditiondata_center
AtlassianJira Service Management Version4.20.14 SwEditionserver
AtlassianJira Service Management Version4.20.15 SwEditiondata_center
AtlassianJira Service Management Version4.20.15 SwEditionserver
AtlassianJira Service Management Version4.20.16 SwEditiondata_center
AtlassianJira Service Management Version4.20.16 SwEditionserver
AtlassianJira Service Management Version4.20.17 SwEditiondata_center
AtlassianJira Service Management Version4.20.17 SwEditionserver
AtlassianJira Service Management Version4.20.18 SwEditiondata_center
AtlassianJira Service Management Version4.20.18 SwEditionserver
AtlassianJira Service Management Version4.20.19 SwEditiondata_center
AtlassianJira Service Management Version4.20.19 SwEditionserver
AtlassianJira Service Management Version4.20.20 SwEditiondata_center
AtlassianJira Service Management Version4.20.20 SwEditionserver
AtlassianJira Service Management Version4.20.21 SwEditiondata_center
AtlassianJira Service Management Version4.20.21 SwEditionserver
AtlassianJira Service Management Version4.20.22 SwEditiondata_center
AtlassianJira Service Management Version4.20.22 SwEditionserver
AtlassianJira Service Management Version4.20.23 SwEditiondata_center
AtlassianJira Service Management Version4.20.23 SwEditionserver
AtlassianJira Service Management Version4.20.24 SwEditiondata_center
AtlassianJira Service Management Version4.20.24 SwEditionserver
AtlassianJira Service Management Version4.20.25 SwEditiondata_center
AtlassianJira Service Management Version4.20.25 SwEditionserver
AtlassianJira Service Management Version4.21.0 SwEditiondata_center
AtlassianJira Service Management Version4.21.0 SwEditionserver
AtlassianJira Service Management Version4.21.1 SwEditiondata_center
AtlassianJira Service Management Version4.21.1 SwEditionserver
AtlassianJira Service Management Version4.22.0 SwEditiondata_center
AtlassianJira Service Management Version4.22.0 SwEditionserver
AtlassianJira Service Management Version4.22.1 SwEditiondata_center
AtlassianJira Service Management Version4.22.1 SwEditionserver
AtlassianJira Service Management Version4.22.2 SwEditiondata_center
AtlassianJira Service Management Version4.22.2 SwEditionserver
AtlassianJira Service Management Version4.22.3 SwEditiondata_center
AtlassianJira Service Management Version4.22.3 SwEditionserver
AtlassianJira Service Management Version4.22.4 SwEditiondata_center
AtlassianJira Service Management Version4.22.4 SwEditionserver
AtlassianJira Service Management Version4.22.6 SwEditiondata_center
AtlassianJira Service Management Version4.22.6 SwEditionserver
AtlassianJira Service Management Version5.0.0 SwEditiondata_center
AtlassianJira Service Management Version5.0.0 SwEditionserver
AtlassianJira Service Management Version5.1.0 SwEditiondata_center
AtlassianJira Service Management Version5.1.0 SwEditionserver
AtlassianJira Service Management Version5.1.1 SwEditiondata_center
AtlassianJira Service Management Version5.1.1 SwEditionserver
AtlassianJira Service Management Version5.2.0 SwEditiondata_center
AtlassianJira Service Management Version5.2.0 SwEditionserver
AtlassianJira Service Management Version5.2.1 SwEditiondata_center
AtlassianJira Service Management Version5.2.1 SwEditionserver
AtlassianJira Service Management Version5.3.0 SwEditiondata_center
AtlassianJira Service Management Version5.3.0 SwEditionserver
AtlassianJira Service Management Version5.3.1 SwEditiondata_center
AtlassianJira Service Management Version5.3.1 SwEditionserver
AtlassianJira Service Management Version5.3.2 SwEditiondata_center
AtlassianJira Service Management Version5.3.2 SwEditionserver
AtlassianJira Service Management Version5.3.3 SwEditiondata_center
AtlassianJira Service Management Version5.3.3 SwEditionserver
AtlassianJira Service Management Version5.4.0 SwEditiondata_center
AtlassianJira Service Management Version5.4.0 SwEditionserver
AtlassianJira Service Management Version5.4.1 SwEditiondata_center
AtlassianJira Service Management Version5.4.1 SwEditionserver
AtlassianJira Service Management Version5.4.2 SwEditiondata_center
AtlassianJira Service Management Version5.4.2 SwEditionserver
AtlassianJira Service Management Version5.4.3 SwEditiondata_center
AtlassianJira Service Management Version5.4.3 SwEditionserver
AtlassianJira Service Management Version5.4.4 SwEditiondata_center
AtlassianJira Service Management Version5.4.4 SwEditionserver
AtlassianJira Service Management Version5.4.5 SwEditiondata_center
AtlassianJira Service Management Version5.4.5 SwEditionserver
AtlassianJira Service Management Version5.4.6 SwEditiondata_center
AtlassianJira Service Management Version5.4.6 SwEditionserver
AtlassianJira Service Management Version5.4.7 SwEditiondata_center
AtlassianJira Service Management Version5.4.7 SwEditionserver
AtlassianJira Service Management Version5.4.8 SwEditiondata_center
AtlassianJira Service Management Version5.4.8 SwEditionserver
AtlassianJira Service Management Version5.4.9 SwEditiondata_center
AtlassianJira Service Management Version5.4.9 SwEditionserver
AtlassianJira Service Management Version5.5.1 SwEditiondata_center
AtlassianJira Service Management Version5.5.1 SwEditionserver
AtlassianJira Service Management Version5.6.0 SwEditiondata_center
AtlassianJira Service Management Version5.6.0 SwEditionserver
AtlassianJira Service Management Version5.7.0 SwEditiondata_center
AtlassianJira Service Management Version5.7.0 SwEditionserver
AtlassianJira Service Management Version5.7.1 SwEditiondata_center
AtlassianJira Service Management Version5.7.1 SwEditionserver
AtlassianJira Service Management Version5.8.0 SwEditiondata_center
AtlassianJira Service Management Version5.8.0 SwEditionserver
AtlassianJira Service Management Version5.8.1 SwEditiondata_center
AtlassianJira Service Management Version5.8.1 SwEditionserver
AtlassianJira Service Management Version5.9.0 SwEditiondata_center
AtlassianJira Service Management Version5.9.0 SwEditionserver
AtlassianJira Service Management Version5.10.0 SwEditiondata_center
AtlassianJira Service Management Version5.10.0 SwEditionserver
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 10.42% 0.929
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://github.com/quartz-scheduler/quartz/issues/467
Third Party Advisory
Issue Tracking