CVE-2019-13990

CRITICALCVSS 9.8/10EPSS 16.63%

Last modified

CVE-2019-13990 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.. EPSS estimates a 16.63% chance of exploitation in the next 30 days.

Description

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
16.63%

96.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SoftwareagQuartz< 2.3.2
OracleApache Batik Mapviewer12.2.0.1
OracleApache Batik Mapviewer18c
OracleApache Batik Mapviewer19c
OracleBanking Enterprise Originations2.7.0
OracleBanking Enterprise Originations2.8.0
OracleBanking Enterprise Product Manufacturing2.7.0
OracleBanking Enterprise Product Manufacturing2.8.0
OracleBanking Payments>= 14.1.0, <= 14.4.0
OracleCommunications Ip Service Activator7.3.0
OracleCommunications Ip Service Activator7.4.0
OracleCommunications Session Route Manager>= 8.2.0, <= 8.2.2
OracleCustomer Management And Segmentation Foundation18.0
OracleDocumaker>= 12.6.0, <= 12.6.4
OracleEnterprise Manager Base Platform13.2.1.0
OracleEnterprise Manager Ops Center12.4.0.0
OracleFlexcube Investor Servicing12.1.0
OracleFlexcube Investor Servicing12.3.0
OracleFlexcube Investor Servicing12.4.0
OracleFlexcube Investor Servicing14.1.0
OracleFlexcube Investor Servicing14.4.0
OracleFlexcube Private Banking12.0.0
OracleFlexcube Private Banking12.1.0
OracleFusion Middleware Mapviewer12.2.1.3.0
OracleGoogle Guava Mapviewer12.2.0.1
OracleGoogle Guava Mapviewer18c
OracleGoogle Guava Mapviewer19c
OracleHyperion Infrastructure Technology11.1.2.4
OracleJd Edwards Enterpriseone Orchestrator<= 9.2.5.3
OraclePrimavera Unifier>= 17.7, <= 17.12
OraclePrimavera Unifier16.1
OraclePrimavera Unifier16.2
OraclePrimavera Unifier18.8
OracleRetail Back Office14.1
OracleRetail Central Office14.1
OracleRetail Integration Bus15.0
OracleRetail Integration Bus16.0
OracleRetail Order Broker15.0
OracleRetail Order Broker16.0
OracleRetail Order Broker18.0
OracleRetail Order Broker19.0
OracleRetail Point-Of-Service14.1
OracleRetail Returns Management14.1
OracleRetail Xstore Point Of Service15.0
OracleRetail Xstore Point Of Service16.0
OracleRetail Xstore Point Of Service17.0
OracleRetail Xstore Point Of Service18.0
OracleRetail Xstore Point Of Service19.0
OracleTerracotta Quartz Scheduler Mapviewer12.2.0.1
OracleTerracotta Quartz Scheduler Mapviewer18c

Showing 50 of 117 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-13990?
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
How severe is CVE-2019-13990?
CVE-2019-13990 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 16.63% probability of exploitation in the next 30 days.
How do I fix CVE-2019-13990?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-13990?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST