CVE-2019-5427
22.04.2019, 21:29
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Vendor | Product | Version |
---|---|---|
mchange | c3p0 | 𝑥 < 0.9.5.2 |
oracle | communications_ip_service_activator | 7.3.0 |
oracle | communications_ip_service_activator | 7.4.0 |
oracle | communications_session_route_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | documaker | 12.6.0 ≤ 𝑥 ≤ 12.6.6 |
oracle | enterprise_manager_base_platform | 13.2.1.0 |
oracle | enterprise_manager_ops_center | 12.4.0.0 |
oracle | flexcube_private_banking | 12.0.0 |
oracle | flexcube_private_banking | 12.1.0 |
oracle | hyperion_infrastructure_technology | 11.1.2.4 |
oracle | retail_xstore_point_of_service | 15.0 |
oracle | retail_xstore_point_of_service | 16.0 |
oracle | retail_xstore_point_of_service | 17.0 |
oracle | retail_xstore_point_of_service | 18.0 |
oracle | retail_xstore_point_of_service | 19.0 |
oracle | webcenter_sites | 12.2.1.3.0 |
oracle | webcenter_sites | 12.2.1.4.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
c3p0 |
|
References