cbcvebase.
CVE-2019-5427
published 2019-04-22

CVE-2019-5427: c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianc3p0< c3p0 0.9.1.2-10.1 (forky)c3p0 0.9.1.2-10.1 (forky)
fedoraprojectfedora
fedoraprojectfedora
mchangec3p0< 0.9.5.40.9.5.4
mchangec3p0
mchangec3p0>= 0 < 0.9.1.2-10.10.9.1.2-10.1
mchangec3p0>= 0 < 0.9.1.2-10.10.9.1.2-10.1
oraclecommunications_ip_service_activator
oraclecommunications_ip_service_activator
oraclecommunications_session_route_manager8.2.0 – 8.2.2
oracledocumaker12.6.0 – 12.6.6
oracleenterprise_manager_base_platform
oracleenterprise_manager_ops_center
oracleflexcube_private_banking
oracleflexcube_private_banking
oraclehyperion_infrastructure_technology
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oraclewebcenter_sites
oraclewebcenter_sites

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH