First published: Fri Jul 26 2019(Updated: )
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rhvm-dependencies | <0:4.4.0-1.el8e | 0:4.4.0-1.el8e |
redhat/quartz | <2.3.2 | 2.3.2 |
IBM Data Risk Manager | <=2.0.6 | |
maven/org.quartz-scheduler:quartz | <2.3.2 | 2.3.2 |
Software AG Quartz | <2.3.2 | |
Apache Batik | =12.2.0.1 | |
Apache Batik | =18c | |
Apache Batik | =19c | |
Oracle Banking Enterprise Originations | =2.7.0 | |
Oracle Banking Enterprise Originations | =2.8.0 | |
Oracle Banking Enterprise Product Manufacturing | =2.7.0 | |
Oracle Banking Enterprise Product Manufacturing | =2.8.0 | |
Oracle Banking Payments | >=14.1.0<=14.4.0 | |
Oracle Communications IP Service Activator | =7.3.0 | |
Oracle Communications IP Service Activator | =7.4.0 | |
oracle communications session route manager | >=8.2.0<=8.2.2 | |
Oracle Customer Management and Segmentation Foundation | =18.0 | |
Oracle Documaker | >=12.6.0<=12.6.4 | |
Oracle Enterprise Manager Base Platform | =13.2.1.0 | |
Oracle Enterprise Manager Ops Center | =12.4.0.0 | |
Oracle FLEXCUBE Investor Servicing | =12.1.0 | |
Oracle FLEXCUBE Investor Servicing | =12.3.0 | |
Oracle FLEXCUBE Investor Servicing | =12.4.0 | |
Oracle FLEXCUBE Investor Servicing | =14.1.0 | |
Oracle FLEXCUBE Investor Servicing | =14.4.0 | |
Oracle FLEXCUBE Private Banking | =12.0.0 | |
Oracle FLEXCUBE Private Banking | =12.1.0 | |
Oracle Spatial and Graph MapViewer | =12.2.1.3.0 | |
oracle google guava mapviewer | =12.2.0.1 | |
oracle google guava mapviewer | =18c | |
oracle google guava mapviewer | =19c | |
oracle hyperion infrastructure technology | =11.1.2.4 | |
Oracle JD Edwards EnterpriseOne Orchestrator | <=9.2.5.3 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =16.1 | |
Oracle Primavera Unifier | =16.2 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Retail Back Office | =14.1 | |
Oracle Retail Central Office | =14.1 | |
Oracle Retail Integration Bus | =15.0 | |
Oracle Retail Integration Bus | =16.0 | |
Oracle Retail Order Broker | =15.0 | |
Oracle Retail Order Broker | =16.0 | |
Oracle Retail Order Broker | =18.0 | |
Oracle Retail Order Broker | =19.0 | |
Oracle Retail Point-of-Sale | =14.1 | |
Oracle Retail Returns Management | =14.1 | |
Oracle Retail Xstore Office Cloud Service | =15.0 | |
Oracle Retail Xstore Office Cloud Service | =16.0 | |
Oracle Retail Xstore Office Cloud Service | =17.0 | |
Oracle Retail Xstore Office Cloud Service | =18.0 | |
Oracle Retail Xstore Office Cloud Service | =19.0 | |
Oracle Terracotta Quartz Scheduler MapViewer | =12.2.0.1 | |
Oracle Terracotta Quartz Scheduler MapViewer | =18c | |
Oracle Terracotta Quartz Scheduler MapViewer | =19c | |
Oracle WebCenter Sites | =12.2.1.3.0 | |
Oracle WebCenter Sites | =12.2.1.4.0 | |
Apache TomEE | =7.1.3 | |
NetApp Active IQ Unified Manager | ||
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp active iq unified manager windows | ||
netapp cloud secure agent | ||
Atlassian Jira Service Desk | =4.20.0 | |
Atlassian Jira Service Desk | =4.20.0 | |
Atlassian Jira Service Desk | =4.20.1 | |
Atlassian Jira Service Desk | =4.20.1 | |
Atlassian Jira Service Desk | =4.20.2 | |
Atlassian Jira Service Desk | =4.20.2 | |
Atlassian Jira Service Desk | =4.20.3 | |
Atlassian Jira Service Desk | =4.20.3 | |
Atlassian Jira Service Desk | =4.20.4 | |
Atlassian Jira Service Desk | =4.20.4 | |
Atlassian Jira Service Desk | =4.20.5 | |
Atlassian Jira Service Desk | =4.20.5 | |
Atlassian Jira Service Desk | =4.20.6 | |
Atlassian Jira Service Desk | =4.20.6 | |
Atlassian Jira Service Desk | =4.20.7 | |
Atlassian Jira Service Desk | =4.20.7 | |
Atlassian Jira Service Desk | =4.20.8 | |
Atlassian Jira Service Desk | =4.20.8 | |
Atlassian Jira Service Desk | =4.20.9 | |
Atlassian Jira Service Desk | =4.20.9 | |
Atlassian Jira Service Desk | =4.20.10 | |
Atlassian Jira Service Desk | =4.20.10 | |
Atlassian Jira Service Desk | =4.20.11 | |
Atlassian Jira Service Desk | =4.20.11 | |
Atlassian Jira Service Desk | =4.20.12 | |
Atlassian Jira Service Desk | =4.20.12 | |
Atlassian Jira Service Desk | =4.20.13 | |
Atlassian Jira Service Desk | =4.20.13 | |
Atlassian Jira Service Desk | =4.20.14 | |
Atlassian Jira Service Desk | =4.20.14 | |
Atlassian Jira Service Desk | =4.20.15 | |
Atlassian Jira Service Desk | =4.20.15 | |
Atlassian Jira Service Desk | =4.20.16 | |
Atlassian Jira Service Desk | =4.20.16 | |
Atlassian Jira Service Desk | =4.20.17 | |
Atlassian Jira Service Desk | =4.20.17 | |
Atlassian Jira Service Desk | =4.20.18 | |
Atlassian Jira Service Desk | =4.20.18 | |
Atlassian Jira Service Desk | =4.20.19 | |
Atlassian Jira Service Desk | =4.20.19 | |
Atlassian Jira Service Desk | =4.20.20 | |
Atlassian Jira Service Desk | =4.20.20 | |
Atlassian Jira Service Desk | =4.20.21 | |
Atlassian Jira Service Desk | =4.20.21 | |
Atlassian Jira Service Desk | =4.20.22 | |
Atlassian Jira Service Desk | =4.20.22 | |
Atlassian Jira Service Desk | =4.20.23 | |
Atlassian Jira Service Desk | =4.20.23 | |
Atlassian Jira Service Desk | =4.20.24 | |
Atlassian Jira Service Desk | =4.20.24 | |
Atlassian Jira Service Desk | =4.20.25 | |
Atlassian Jira Service Desk | =4.20.25 | |
Atlassian Jira Service Desk | =4.21.0 | |
Atlassian Jira Service Desk | =4.21.0 | |
Atlassian Jira Service Desk | =4.21.1 | |
Atlassian Jira Service Desk | =4.21.1 | |
Atlassian Jira Service Desk | =4.22.0 | |
Atlassian Jira Service Desk | =4.22.0 | |
Atlassian Jira Service Desk | =4.22.1 | |
Atlassian Jira Service Desk | =4.22.1 | |
Atlassian Jira Service Desk | =4.22.2 | |
Atlassian Jira Service Desk | =4.22.2 | |
Atlassian Jira Service Desk | =4.22.3 | |
Atlassian Jira Service Desk | =4.22.3 | |
Atlassian Jira Service Desk | =4.22.4 | |
Atlassian Jira Service Desk | =4.22.4 | |
Atlassian Jira Service Desk | =4.22.6 | |
Atlassian Jira Service Desk | =4.22.6 | |
Atlassian Jira Service Desk | =5.0.0 | |
Atlassian Jira Service Desk | =5.0.0 | |
Atlassian Jira Service Desk | =5.1.0 | |
Atlassian Jira Service Desk | =5.1.0 | |
Atlassian Jira Service Desk | =5.1.1 | |
Atlassian Jira Service Desk | =5.1.1 | |
Atlassian Jira Service Desk | =5.2.0 | |
Atlassian Jira Service Desk | =5.2.0 | |
Atlassian Jira Service Desk | =5.2.1 | |
Atlassian Jira Service Desk | =5.2.1 | |
Atlassian Jira Service Desk | =5.3.0 | |
Atlassian Jira Service Desk | =5.3.0 | |
Atlassian Jira Service Desk | =5.3.1 | |
Atlassian Jira Service Desk | =5.3.1 | |
Atlassian Jira Service Desk | =5.3.2 | |
Atlassian Jira Service Desk | =5.3.2 | |
Atlassian Jira Service Desk | =5.3.3 | |
Atlassian Jira Service Desk | =5.3.3 | |
Atlassian Jira Service Desk | =5.4.0 | |
Atlassian Jira Service Desk | =5.4.0 | |
Atlassian Jira Service Desk | =5.4.1 | |
Atlassian Jira Service Desk | =5.4.1 | |
Atlassian Jira Service Desk | =5.4.2 | |
Atlassian Jira Service Desk | =5.4.2 | |
Atlassian Jira Service Desk | =5.4.3 | |
Atlassian Jira Service Desk | =5.4.3 | |
Atlassian Jira Service Desk | =5.4.4 | |
Atlassian Jira Service Desk | =5.4.4 | |
Atlassian Jira Service Desk | =5.4.5 | |
Atlassian Jira Service Desk | =5.4.5 | |
Atlassian Jira Service Desk | =5.4.6 | |
Atlassian Jira Service Desk | =5.4.6 | |
Atlassian Jira Service Desk | =5.4.7 | |
Atlassian Jira Service Desk | =5.4.7 | |
Atlassian Jira Service Desk | =5.4.8 | |
Atlassian Jira Service Desk | =5.4.8 | |
Atlassian Jira Service Desk | =5.4.9 | |
Atlassian Jira Service Desk | =5.4.9 | |
Atlassian Jira Service Desk | =5.5.1 | |
Atlassian Jira Service Desk | =5.5.1 | |
Atlassian Jira Service Desk | =5.6.0 | |
Atlassian Jira Service Desk | =5.6.0 | |
Atlassian Jira Service Desk | =5.7.0 | |
Atlassian Jira Service Desk | =5.7.0 | |
Atlassian Jira Service Desk | =5.7.1 | |
Atlassian Jira Service Desk | =5.7.1 | |
Atlassian Jira Service Desk | =5.8.0 | |
Atlassian Jira Service Desk | =5.8.0 | |
Atlassian Jira Service Desk | =5.8.1 | |
Atlassian Jira Service Desk | =5.8.1 | |
Atlassian Jira Service Desk | =5.9.0 | |
Atlassian Jira Service Desk | =5.9.0 | |
Atlassian Jira Service Desk | =5.10.0 | |
Atlassian Jira Service Desk | =5.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-13990 is classified as a moderate severity vulnerability.
To remediate CVE-2019-13990, upgrade to versions 2.3.2 or higher of the affected software.
CVE-2019-13990 affects Terracotta Quartz Scheduler versions up to and including 2.3.0.
CVE-2019-13990 is an XML External Entity (XXE) vulnerability that allows attackers to exploit user-controlled job descriptions.
Yes, CVE-2019-13990 can potentially be exploited remotely due to its nature as an XXE vulnerability.