CVE-2019-13990XML External Entity (XXE) Injection in Quartz

Severity
9.8CRITICALNVD
EPSS
17.2%
top 4.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateApr 15

Description

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages29 packages

NVDsoftwareag/quartz< 2.3.2
NVDoracle/documaker12.6.012.6.4
NVDoracle/banking_payments14.1.014.4.0
NVDoracle/primavera_unifier17.717.12+3

Patches

🔴Vulnerability Details

4
GHSA
XML external entity injection in Terracotta Quartz Scheduler2020-07-01
OSV
XML external entity injection in Terracotta Quartz Scheduler2020-07-01
CVEList
CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor2019-07-26
OSV
CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor2019-07-26

📋Vendor Advisories

10
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Quartz) — CVE-2019-139902024-04-15
Oracle
Oracle Oracle Analytics Risk Matrix: Framework (Quartz) — CVE-2019-139902023-07-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Terracotta Quartz Scheduler) — CVE-2019-139902021-10-15
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Quartz) — CVE-2019-139902021-07-15
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Connector Framework (Quartz) — CVE-2019-139902021-01-15

💬Community

2
Bugzilla
CVE-2019-13990 quartz: libquartz: XXE attacks via job description [fedora-all]2020-03-18
Bugzilla
CVE-2019-13990 libquartz: XXE attacks via job description2020-02-10
CVE-2019-13990 — XML External Entity (XXE) Injection | cvebase