CVE-2019-13990
published 2019-07-26CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
16.20%
96.6th percentile
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Affected
117 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomee | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Quartz) — CVE-2019-13990
vendor_oracle·2024-04-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Quartz) — CVE-2019-13990
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Analytics Risk Matrix: Framework (Quartz) — CVE-2019-13990
vendor_oracle·2023-07-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Analytics Risk Matrix: Framework (Quartz) — CVE-2019-13990
Oracle Oracle Analytics Risk Matrix: Framework (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Terracotta Quartz Scheduler) — CVE-2019-13990
vendor_oracle·2021-10-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Terracotta Quartz Scheduler) — CVE-2019-13990
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Terracotta Quartz Scheduler) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Quartz) — CVE-2019-13990
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Quartz) — CVE-2019-13990
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Connector Framework (Quartz) — CVE-2019-13990
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Connector Framework (Quartz) — CVE-2019-13990
Oracle Oracle Enterprise Manager Risk Matrix: Connector Framework (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: Core (Quartz Scheduler) — CVE-2019-13990
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Communications Risk Matrix: Core (Quartz Scheduler) — CVE-2019-13990
Oracle Oracle Communications Risk Matrix: Core (Quartz Scheduler) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Database Server Risk Matrix: MapViewer (Terracotta Quartz Scheduler, Apache Batik, Google Guava) — CVE-2019-13990
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Database Server Risk Matrix: MapViewer (Terracotta Quartz Scheduler, Apache Batik, Google Guava) — CVE-2019-13990
Oracle Oracle Database Server Risk Matrix: MapViewer (Terracotta Quartz Scheduler, Apache Batik, Google Guava) vulnerability
CVE: CVE-2019-13990
CVSS: 0.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Infrastructure (Quartz) — CVE-2019-13990
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Infrastructure (Quartz) — CVE-2019-13990
Oracle Oracle Construction and Engineering Risk Matrix: Infrastructure (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
libquartz: XXE attacks via job description
vendor_redhat·2019-07-26·CVSS 9.8
CVE-2019-13990 [CRITICAL] CWE-611 libquartz: XXE attacks via job description
libquartz: XXE attacks via job description
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
The Terracotta Quartz Scheduler is susceptible to an XML external entity attack (XXE) through a job description. This issue stems from inadequate handling of XML external entity (XXE) declarations in the initDocumentParser function within xml/XMLSchedulingDataProcessor.java. By enticing a victim to access a maliciously crafted job description (containing XML content), a remote attacker could exploit this vulnerability to execute an XXE attack on the targeted system.
Statement: Red Hat Satellite 6 uses a vulnerable version of libquartz as a dependency for Candlepin. However, the entry is not used, and t
Debian
CVE-2019-13990: libquartz-java - initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz S...
vendor_debian·2019·CVSS 9.8
CVE-2019-13990 [CRITICAL] CVE-2019-13990: libquartz-java - initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz S...
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Scope: local
bookworm: resolved (fixed in 1:1.8.6-8)
bullseye: open
sid: resolved (fixed in 1:1.8.6-8)
trixie: resolved (fixed in 1:1.8.6-8)
GHSA
XML external entity injection in Terracotta Quartz Scheduler
ghsa·2020-07-01
CVE-2019-13990 [CRITICAL] CWE-611 XML external entity injection in Terracotta Quartz Scheduler
XML external entity injection in Terracotta Quartz Scheduler
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
OSV
XML external entity injection in Terracotta Quartz Scheduler
osv·2020-07-01
CVE-2019-13990 [CRITICAL] XML external entity injection in Terracotta Quartz Scheduler
XML external entity injection in Terracotta Quartz Scheduler
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
OSV
CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor
osv·2019-07-26·CVSS 9.8
CVE-2019-13990 [CRITICAL] CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Security Updates, April 2024: Critical Patch | Qualys
blogs_qualys·2024-04-17
Oracle Security Updates, April 2024: Critical Patch | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle released its second quarterly edition of Critical Patch Update, which contains patches for 441 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the second quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 93, constituting about 21% of the total patches released. Oracle Fusion Middleware and Oracle Financial Services Applicat
Qualys
Oracle Patch Update, April 2024 Security Update Review
blogs_qualys·2024-04-17
Oracle Patch Update, April 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle released its second quarterly edition of Critical Patch Update, which contains patches for 441 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the second quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 93, constituting about 21% of the total patches released. Oracle Fusion Middleware and Oracle Financial Services Applications fo
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed, with
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followe
Bugzilla
CVE-2019-13990 quartz: libquartz: XXE attacks via job description [fedora-all]
bugzilla·2020-03-18·CVSS 9.8
CVE-2019-13990 [CRITICAL] CVE-2019-13990 quartz: libquartz: XXE attacks via job description [fedora-all]
CVE-2019-13990 quartz: libquartz: XXE attacks via job description [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2019-13990 libquartz: XXE attacks via job description
bugzilla·2020-02-10·CVSS 9.8
CVE-2019-13990 [CRITICAL] CVE-2019-13990 libquartz: XXE attacks via job description
CVE-2019-13990 libquartz: XXE attacks via job description
A vulnerability was found in initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Reference:
https://github.com/quartz-scheduler/quartz/issues/467
https://lists.apache.org/thread.html/172d405e556e2f1204be126bb3eb28c5115af91bcc1651b4e870bb82@%3Cdev.tomee.apache.org%3E
https://lists.apache.org/thread.html/1870324fea41ea68cff2fd1bf6ee2747432dc1d9d22a22cc681e0ec3@%3Cdev.tomee.apache.org%3E
https://lists.apache.org/thread.html/6b6e3480b19856365fb5eef03aa0915a4679de4b019a1e975502d949@%3Cdev.tomee.apache.org%3E
https://lists.apache.org/thread.html/e493e718a50f21201e05e82d42a8796b4046e83f0d286b90e58e0629@%3Cdev.tomee.apache.org%3E
https://lists.apa
https://confluence.atlassian.com/security/ssot-117-cve-2019-13990-xxe-xml-external-entity-injection-vulnerability-in-jira-service-management-data-center-and-jira-service-management-server-1295385959.htmlhttps://github.com/quartz-scheduler/quartz/issues/467https://lists.apache.org/thread.html/172d405e556e2f1204be126bb3eb28c5115af91bcc1651b4e870bb82%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/1870324fea41ea68cff2fd1bf6ee2747432dc1d9d22a22cc681e0ec3%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/6b6e3480b19856365fb5eef03aa0915a4679de4b019a1e975502d949%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/e493e718a50f21201e05e82d42a8796b4046e83f0d286b90e58e0629%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/f74b170d3d58d7a24db1afd3908bb0ab58a3900e16e73275674cdfaf%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r21df13c8bd2c2eae4b9661aae814c4a2a814d1f7875c765b8b115c9a%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r3a6884e8d819f32cde8c07b98934de3e80467859880f784950bf44cf%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re9b56ac1934d7bf16afc83eac1c39c98c1b20b4b15891dce923bf8aa%40%3Ccommits.tomee.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20221028-0002/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://confluence.atlassian.com/security/ssot-117-cve-2019-13990-xxe-xml-external-entity-injection-vulnerability-in-jira-service-management-data-center-and-jira-service-management-server-1295385959.htmlhttps://github.com/quartz-scheduler/quartz/issues/467https://lists.apache.org/thread.html/172d405e556e2f1204be126bb3eb28c5115af91bcc1651b4e870bb82%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/1870324fea41ea68cff2fd1bf6ee2747432dc1d9d22a22cc681e0ec3%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/6b6e3480b19856365fb5eef03aa0915a4679de4b019a1e975502d949%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/e493e718a50f21201e05e82d42a8796b4046e83f0d286b90e58e0629%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/f74b170d3d58d7a24db1afd3908bb0ab58a3900e16e73275674cdfaf%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r21df13c8bd2c2eae4b9661aae814c4a2a814d1f7875c765b8b115c9a%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r3a6884e8d819f32cde8c07b98934de3e80467859880f784950bf44cf%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re9b56ac1934d7bf16afc83eac1c39c98c1b20b4b15891dce923bf8aa%40%3Ccommits.tomee.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20221028-0002/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2019-07-26
Published