CVE-2019-5427

EUVD-2019-0409
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
XML Entity Expansion
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
mchangec3p0
𝑥
< 0.9.5.4
oraclecommunications_ip_service_activator
7.3.0
oraclecommunications_ip_service_activator
7.4.0
oraclecommunications_session_route_manager
8.2.0 ≤
𝑥
≤ 8.2.2
oracledocumaker
12.6.0 ≤
𝑥
≤ 12.6.6
oracleenterprise_manager_base_platform
13.2.1.0
oracleenterprise_manager_ops_center
12.4.0.0
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oraclehyperion_infrastructure_technology
11.1.2.4
oracleretail_xstore_point_of_service
15.0
oracleretail_xstore_point_of_service
16.0
oracleretail_xstore_point_of_service
17.0
oracleretail_xstore_point_of_service
18.0
oracleretail_xstore_point_of_service
19.0
oraclewebcenter_sites
12.2.1.3.0
oraclewebcenter_sites
12.2.1.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
c3p0
bookworm
no-dsa
bullseye
no-dsa
buster
no-dsa
jessie
no-dsa
sid
vulnerable
stretch
no-dsa
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
c3p0
bionic
Fixed 0.9.1.2-9+deb8u1ubuntu0.18.04.1
released
cosmic
ignored
disco
ignored
eoan
ignored
focal
Fixed 0.9.1.2-10ubuntu0.20.04.1
released
groovy
ignored
hirsute
ignored
impish
Fixed 0.9.1.2-10ubuntu0.21.10.1
released
jammy
needed
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needed
trusty
needed
xenial
Fixed 0.9.1.2-9+deb8u1ubuntu0.16.04.1~esm1
released