cbcvebase.
CVE-2019-5427
published 2019-04-22

CVE-2019-5427: c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.88%
91.1th percentile
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianc3p0< c3p0 0.9.1.2-10.1 (forky)c3p0 0.9.1.2-10.1 (forky)
fedoraprojectfedora
fedoraprojectfedora
mchangec3p0< 0.9.5.40.9.5.4
mchangec3p0
mchangec3p0>= 0 < 0.9.1.2-10.10.9.1.2-10.1
mchangec3p0>= 0 < 0.9.1.2-10.10.9.1.2-10.1
oraclecommunications_ip_service_activator
oraclecommunications_ip_service_activator
oraclecommunications_session_route_manager8.2.0 – 8.2.2
oracledocumaker12.6.0 – 12.6.6
oracleenterprise_manager_base_platform
oracleenterprise_manager_ops_center
oracleflexcube_private_banking
oracleflexcube_private_banking
oraclehyperion_infrastructure_technology
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oraclewebcenter_sites
oraclewebcenter_sites

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.