CVE-2019-5427

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
XML Entity Expansion
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
hackeroneCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
mchangec3p0
𝑥
< 0.9.5.2
oraclecommunications_ip_service_activator
7.3.0
oraclecommunications_ip_service_activator
7.4.0
oraclecommunications_session_route_manager
8.2.0 ≤
𝑥
≤ 8.2.2
oracledocumaker
12.6.0 ≤
𝑥
≤ 12.6.6
oracleenterprise_manager_base_platform
13.2.1.0
oracleenterprise_manager_ops_center
12.4.0.0
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oraclehyperion_infrastructure_technology
11.1.2.4
oracleretail_xstore_point_of_service
15.0
oracleretail_xstore_point_of_service
16.0
oracleretail_xstore_point_of_service
17.0
oracleretail_xstore_point_of_service
18.0
oracleretail_xstore_point_of_service
19.0
oraclewebcenter_sites
12.2.1.3.0
oraclewebcenter_sites
12.2.1.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
c3p0
sid
vulnerable
trixie
vulnerable
bookworm
no-dsa
bullseye
no-dsa
buster
no-dsa
stretch
no-dsa
jessie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
c3p0
noble
needed
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needed
impish
Fixed 0.9.1.2-10ubuntu0.21.10.1
released
hirsute
ignored
groovy
ignored
focal
Fixed 0.9.1.2-10ubuntu0.20.04.1
released
eoan
ignored
disco
ignored
cosmic
ignored
bionic
Fixed 0.9.1.2-9+deb8u1ubuntu0.18.04.1
released
xenial
Fixed 0.9.1.2-9+deb8u1ubuntu0.16.04.1~esm1
released
trusty
needed