CVE-2014-0191XML External Entity (XXE) Injection in Oracle Fusion Middleware

Severity
4.3MEDIUMNVD
EPSS
0.8%
top 25.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21
Latest updateMay 17

Description

The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDoracle/fusion_middleware11.1.1.7.0, 12.1.2.0.0, 12.1.3.0.0+2
Debianxmlsoft/libxml2< 2.9.1+dfsg1-4+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hwp3-c628-9f7v: The xmlParserHandlePEReference function in parser2022-05-17
OSV
CVE-2014-0191: The xmlParserHandlePEReference function in parser2015-01-21
CVEList
CVE-2014-0191: The xmlParserHandlePEReference function in parser2015-01-21

📋Vendor Advisories

6
Ubuntu
libxml2 vulnerability2014-05-15
Red Hat
libxml2: external parameter entity loaded when entity substitution is disabled2014-05-06
Debian
CVE-2014-0191: libxml2 - The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as ...2014
Apple
CVE-2014-0191: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple
CVE-2014-0191: iOS 8.4.1

💬Community

4
Bugzilla
CVE-2014-0191 mingw-libxml2: libxml2: external parameter entity loaded when entity substitution is disabled [epel-7]2015-02-11
Bugzilla
CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled [fedora-all]2014-06-10
Bugzilla
CVE-2014-0191 mingw-libxml2: libxml2: external parameter entity loaded when entity substitution is disabled [fedora-all]2014-06-10
Bugzilla
CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled2014-04-24
CVE-2014-0191 — XML External Entity (XXE) Injection | cvebase