CVE-2019-13990
published 2019-07-26CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
16.20%
96.7th percentile
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Affected
117 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomee | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Quartz) — CVE-2019-13990
vendor_oracle·2024-04-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Quartz) — CVE-2019-13990
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Analytics Risk Matrix: Framework (Quartz) — CVE-2019-13990
vendor_oracle·2023-07-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Analytics Risk Matrix: Framework (Quartz) — CVE-2019-13990
Oracle Oracle Analytics Risk Matrix: Framework (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Terracotta Quartz Scheduler) — CVE-2019-13990
vendor_oracle·2021-10-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Terracotta Quartz Scheduler) — CVE-2019-13990
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Terracotta Quartz Scheduler) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Quartz) — CVE-2019-13990
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Quartz) — CVE-2019-13990
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Connector Framework (Quartz) — CVE-2019-13990
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Connector Framework (Quartz) — CVE-2019-13990
Oracle Oracle Enterprise Manager Risk Matrix: Connector Framework (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: Core (Quartz Scheduler) — CVE-2019-13990
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Communications Risk Matrix: Core (Quartz Scheduler) — CVE-2019-13990
Oracle Oracle Communications Risk Matrix: Core (Quartz Scheduler) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Database Server Risk Matrix: MapViewer (Terracotta Quartz Scheduler, Apache Batik, Google Guava) — CVE-2019-13990
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Database Server Risk Matrix: MapViewer (Terracotta Quartz Scheduler, Apache Batik, Google Guava) — CVE-2019-13990
Oracle Oracle Database Server Risk Matrix: MapViewer (Terracotta Quartz Scheduler, Apache Batik, Google Guava) vulnerability
CVE: CVE-2019-13990
CVSS: 0.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Infrastructure (Quartz) — CVE-2019-13990
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Infrastructure (Quartz) — CVE-2019-13990
Oracle Oracle Construction and Engineering Risk Matrix: Infrastructure (Quartz) vulnerability
CVE: CVE-2019-13990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
libquartz: XXE attacks via job description
vendor_redhat·2019-07-26·CVSS 9.8
CVE-2019-13990 [CRITICAL] CWE-611 libquartz: XXE attacks via job description
libquartz: XXE attacks via job description
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
The Terracotta Quartz Scheduler is susceptible to an XML external entity attack (XXE) through a job description. This issue stems from inadequate handling of XML external entity (XXE) declarations in the initDocumentParser function within xml/XMLSchedulingDataProcessor.java. By enticing a victim to access a maliciously crafted job description (containing XML content), a remote attacker could exploit this vulnerability to execute an XXE attack on the targeted system.
Statement: Red Hat Satellite 6 uses a vulnerable version of libquartz as a dependency for Candlepin. However, the entry is not used, and t
Debian
CVE-2019-13990: libquartz-java - initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz S...
vendor_debian·2019·CVSS 9.8
CVE-2019-13990 [CRITICAL] CVE-2019-13990: libquartz-java - initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz S...
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Scope: local
bookworm: resolved (fixed in 1:1.8.6-8)
bullseye: open
sid: resolved (fixed in 1:1.8.6-8)
trixie: resolved (fixed in 1:1.8.6-8)
VulDB
Oracle Customer Management/Segmentation Foundation 18 Segment xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Customer Management/Segmentation Foundation 18 Segment xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability described as very critical has been identified in Oracle Customer Management and Segmentation Foundation 18. This affects an unknown function of the component Segment. Such manipulation leads to xml external entity reference.
This vulnerability is listed as CVE-2019-13990. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
VulDB
Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.5.3 Quartz xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.5.3 Quartz xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability, which was classified as very critical, was found in Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.5.3. Affected by this vulnerability is an unknown functionality of the component Quartz. Executing a manipulation can lead to xml external entity reference.
This vulnerability is handled as CVE-2019-13990. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
VulDB
Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 Framework xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 Framework xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability labeled as very critical has been found in Oracle Business Intelligence Enterprise Edition 12.2.1.4.0. The impacted element is an unknown function of the component Framework. The manipulation results in xml external entity reference.
This vulnerability is identified as CVE-2019-13990. The attack can be executed remotely. There is not any exploit available.
VulDB
Oracle Hyperion Infrastructure Technology 11.1.2.4 Common Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Hyperion Infrastructure Technology 11.1.2.4 Common Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability, which was classified as very critical, has been found in Oracle Hyperion Infrastructure Technology 11.1.2.4. This issue affects some unknown processing of the component Common Security. This manipulation causes xml external entity reference.
This vulnerability is tracked as CVE-2019-13990. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
VulDB
Oracle Banking Payments 14.1.x/14.2.x/14.3.x/14.4.0 Core xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Banking Payments 14.1.x/14.2.x/14.3.x/14.4.0 Core xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability classified as very critical has been found in Oracle Banking Payments 14.1.x/14.2.x/14.3.x/14.4.0. This vulnerability affects unknown code of the component Core. This manipulation causes xml external entity reference.
This vulnerability is tracked as CVE-2019-13990. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
VulDB
Oracle Retail Point-of-Service 14.1 Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Retail Point-of-Service 14.1 Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability was found in Oracle Retail Point-of-Service 14.1. It has been classified as very critical. Affected by this issue is some unknown functionality of the component Security. Performing a manipulation results in xml external entity reference.
This vulnerability is reported as CVE-2019-13990. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
VulDB
Oracle Enterprise Manager Base Platform 13.2.1.0 Connector Framework xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Enterprise Manager Base Platform 13.2.1.0 Connector Framework xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability was found in Oracle Enterprise Manager Base Platform 13.2.1.0. It has been classified as very critical. This vulnerability affects unknown code of the component Connector Framework. The manipulation leads to xml external entity reference.
This vulnerability is referenced as CVE-2019-13990. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
VulDB
Oracle WebCenter Sites 12.2.1.3.0/12.2.1.4.0 Terracotta Quartz Scheduler xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle WebCenter Sites 12.2.1.3.0/12.2.1.4.0 Terracotta Quartz Scheduler xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability described as very critical has been identified in Oracle WebCenter Sites 12.2.1.3.0/12.2.1.4.0. This issue affects some unknown processing of the component Terracotta Quartz Scheduler. Such manipulation leads to xml external entity reference.
This vulnerability is documented as CVE-2019-13990. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
VulDB
Oracle Retail Returns Management 14.1 Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Retail Returns Management 14.1 Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability was found in Oracle Retail Returns Management 14.1. It has been rated as very critical. This vulnerability affects unknown code of the component Security. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2019-13990. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
VulDB
Oracle Retail Order Broker 15.0/16.0/18.0/19.0 Order Broker Foundation xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Retail Order Broker 15.0/16.0/18.0/19.0 Order Broker Foundation xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability was found in Oracle Retail Order Broker 15.0/16.0/18.0/19.0 and classified as very critical. Affected by this vulnerability is an unknown functionality of the component Order Broker Foundation. Such manipulation leads to xml external entity reference.
This vulnerability is documented as CVE-2019-13990. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Communications IP Service Activator 7.3.0/7.4.0 Netwok Processor Configuration Management xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Communications IP Service Activator 7.3.0/7.4.0 Netwok Processor Configuration Management xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability marked as very critical has been reported in Oracle Communications IP Service Activator 7.3.0/7.4.0. Affected is an unknown function of the component Netwok Processor Configuration Management. This manipulation causes xml external entity reference.
This vulnerability appears as CVE-2019-13990. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
VulDB
Oracle Retail Back Office 14.1 Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Retail Back Office 14.1 Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability, which was classified as very critical, has been found in Oracle Retail Back Office 14.1. This affects an unknown function of the component Security. The manipulation leads to xml external entity reference.
This vulnerability is listed as CVE-2019-13990. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
VulDB
Oracle Retail Xstore Point of Service up to 19.0 Xenvironment xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Retail Xstore Point of Service up to 19.0 Xenvironment xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability categorized as very critical has been discovered in Oracle Retail Xstore Point of Service 15.0/16.0/17.0/18.0/19.0. The impacted element is an unknown function of the component Xenvironment. The manipulation results in xml external entity reference.
This vulnerability was named CVE-2019-13990. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
VulDB
Oracle FLEXCUBE Investor Servicing up to 14.1.0 Infrastructure xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle FLEXCUBE Investor Servicing up to 14.1.0 Infrastructure xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability was found in Oracle FLEXCUBE Investor Servicing 12.1.0/12.3.0/12.4.0/14.0.0/14.1.0 and classified as very critical. This affects an unknown function of the component Infrastructure. The manipulation results in xml external entity reference.
This vulnerability is reported as CVE-2019-13990. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
VulDB
Oracle FLEXCUBE Private Banking 12.0.0/12.1.0 Core xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle FLEXCUBE Private Banking 12.0.0/12.1.0 Core xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability was found in Oracle FLEXCUBE Private Banking 12.0.0/12.1.0. It has been classified as very critical. This impacts an unknown function of the component Core. This manipulation causes xml external entity reference.
This vulnerability appears as CVE-2019-13990. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
VulDB
Oracle Communications Session Route Manager 8.2.0/8.2.1/8.2.2 xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Communications Session Route Manager 8.2.0/8.2.1/8.2.2 xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability identified as critical has been detected in Oracle Communications Session Route Manager 8.2.0/8.2.1/8.2.2. Impacted is an unknown function. The manipulation leads to xml external entity reference.
This vulnerability is referenced as CVE-2019-13990. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
VulDB
Oracle Database 12.2.0.1/18c/19c MapViewer xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Database 12.2.0.1/18c/19c MapViewer xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability classified as problematic has been found in Oracle Database 12.2.0.1/18c/19c. The affected element is an unknown function of the component MapViewer. The manipulation leads to xml external entity reference.
This vulnerability is uniquely identified as CVE-2019-13990. Local access is required to approach this attack. No exploit exists.
It is recommended to upgrade the affected component.
VulDB
Oracle Retail Central Office 14.1 Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Retail Central Office 14.1 Security xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability, which was classified as very critical, was found in Oracle Retail Central Office 14.1. This impacts an unknown function of the component Security. The manipulation results in xml external entity reference.
This vulnerability is cataloged as CVE-2019-13990. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
VulDB
Oracle Documaker up to 12.6.4 Terracotta Quartz Scheduler xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Documaker up to 12.6.4 Terracotta Quartz Scheduler xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability categorized as very critical has been discovered in Oracle Documaker 12.6.0/12.6.1/12.6.2/12.6.3/12.6.4. Affected by this issue is some unknown functionality of the component Terracotta Quartz Scheduler. The manipulation results in xml external entity reference.
This vulnerability was named CVE-2019-13990. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
VulDB
Oracle Enterprise Manager Ops Center 12.4.0.0 Agent Provisioning xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Enterprise Manager Ops Center 12.4.0.0 Agent Provisioning xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability was found in Oracle Enterprise Manager Ops Center 12.4.0.0 and classified as critical. The impacted element is an unknown function of the component Agent Provisioning. The manipulation results in xml external entity reference.
This vulnerability is cataloged as CVE-2019-13990. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Retail Integration Bus 15.0/16.0 RIB Kernal xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
vuldb·2026-07-21·CVSS 9.8
CVE-2019-13990 [CRITICAL] Oracle Retail Integration Bus 15.0/16.0 RIB Kernal xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)
A vulnerability was found in Oracle Retail Integration Bus 15.0/16.0 and classified as very critical. This vulnerability affects unknown code of the component RIB Kernal. Such manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2019-13990. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
XML external entity injection in Terracotta Quartz Scheduler
ghsa·2020-07-01
CVE-2019-13990 [CRITICAL] CWE-611 XML external entity injection in Terracotta Quartz Scheduler
XML external entity injection in Terracotta Quartz Scheduler
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
OSV
XML external entity injection in Terracotta Quartz Scheduler
osv·2020-07-01
CVE-2019-13990 [CRITICAL] XML external entity injection in Terracotta Quartz Scheduler
XML external entity injection in Terracotta Quartz Scheduler
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
OSV
CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor
osv·2019-07-26·CVSS 9.8
CVE-2019-13990 [CRITICAL] CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Security Updates, April 2024: Critical Patch | Qualys
blogs_qualys·2024-04-17
Oracle Security Updates, April 2024: Critical Patch | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle released its second quarterly edition of Critical Patch Update, which contains patches for 441 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the second quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 93, constituting about 21% of the total patches released. Oracle Fusion Middleware and Oracle Financial Services Applicat
Qualys
Oracle Patch Update, April 2024 Security Update Review
blogs_qualys·2024-04-17
Oracle Patch Update, April 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle released its second quarterly edition of Critical Patch Update, which contains patches for 441 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the second quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 93, constituting about 21% of the total patches released. Oracle Fusion Middleware and Oracle Financial Services Applications fo
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed, with
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followe
Bugzilla
CVE-2019-13990 quartz: libquartz: XXE attacks via job description [fedora-all]
bugzilla·2020-03-18·CVSS 9.8
CVE-2019-13990 [CRITICAL] CVE-2019-13990 quartz: libquartz: XXE attacks via job description [fedora-all]
CVE-2019-13990 quartz: libquartz: XXE attacks via job description [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2019-13990 libquartz: XXE attacks via job description
bugzilla·2020-02-10·CVSS 9.8
CVE-2019-13990 [CRITICAL] CVE-2019-13990 libquartz: XXE attacks via job description
CVE-2019-13990 libquartz: XXE attacks via job description
A vulnerability was found in initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Reference:
https://github.com/quartz-scheduler/quartz/issues/467
https://lists.apache.org/thread.html/172d405e556e2f1204be126bb3eb28c5115af91bcc1651b4e870bb82@%3Cdev.tomee.apache.org%3E
https://lists.apache.org/thread.html/1870324fea41ea68cff2fd1bf6ee2747432dc1d9d22a22cc681e0ec3@%3Cdev.tomee.apache.org%3E
https://lists.apache.org/thread.html/6b6e3480b19856365fb5eef03aa0915a4679de4b019a1e975502d949@%3Cdev.tomee.apache.org%3E
https://lists.apache.org/thread.html/e493e718a50f21201e05e82d42a8796b4046e83f0d286b90e58e0629@%3Cdev.tomee.apache.org%3E
https://lists.apa
https://confluence.atlassian.com/security/ssot-117-cve-2019-13990-xxe-xml-external-entity-injection-vulnerability-in-jira-service-management-data-center-and-jira-service-management-server-1295385959.htmlhttps://github.com/quartz-scheduler/quartz/issues/467https://lists.apache.org/thread.html/172d405e556e2f1204be126bb3eb28c5115af91bcc1651b4e870bb82%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/1870324fea41ea68cff2fd1bf6ee2747432dc1d9d22a22cc681e0ec3%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/6b6e3480b19856365fb5eef03aa0915a4679de4b019a1e975502d949%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/e493e718a50f21201e05e82d42a8796b4046e83f0d286b90e58e0629%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/f74b170d3d58d7a24db1afd3908bb0ab58a3900e16e73275674cdfaf%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r21df13c8bd2c2eae4b9661aae814c4a2a814d1f7875c765b8b115c9a%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r3a6884e8d819f32cde8c07b98934de3e80467859880f784950bf44cf%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re9b56ac1934d7bf16afc83eac1c39c98c1b20b4b15891dce923bf8aa%40%3Ccommits.tomee.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20221028-0002/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://confluence.atlassian.com/security/ssot-117-cve-2019-13990-xxe-xml-external-entity-injection-vulnerability-in-jira-service-management-data-center-and-jira-service-management-server-1295385959.htmlhttps://github.com/quartz-scheduler/quartz/issues/467https://lists.apache.org/thread.html/172d405e556e2f1204be126bb3eb28c5115af91bcc1651b4e870bb82%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/1870324fea41ea68cff2fd1bf6ee2747432dc1d9d22a22cc681e0ec3%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/6b6e3480b19856365fb5eef03aa0915a4679de4b019a1e975502d949%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/e493e718a50f21201e05e82d42a8796b4046e83f0d286b90e58e0629%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/f74b170d3d58d7a24db1afd3908bb0ab58a3900e16e73275674cdfaf%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r21df13c8bd2c2eae4b9661aae814c4a2a814d1f7875c765b8b115c9a%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r3a6884e8d819f32cde8c07b98934de3e80467859880f784950bf44cf%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re9b56ac1934d7bf16afc83eac1c39c98c1b20b4b15891dce923bf8aa%40%3Ccommits.tomee.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20221028-0002/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2019-07-26
Published