Back to Database
Status published
Unknown
CVE-2019-13990
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows...
Vulnerability Description
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13990
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.apache.org/thread.html/e493e718a50f21201e05e82d42a8796b4046e83f0d286b90e58e0629%40%3Cdev.tomee.apache.org%3E
- https://lists.apache.org/thread.html/1870324fea41ea68cff2fd1bf6ee2747432dc1d9d22a22cc681e0ec3%40%3Cdev.tomee.apache.org%3E
- https://lists.apache.org/thread.html/6b6e3480b19856365fb5eef03aa0915a4679de4b019a1e975502d949%40%3Cdev.tomee.apache.org%3E
- https://lists.apache.org/thread.html/f74b170d3d58d7a24db1afd3908bb0ab58a3900e16e73275674cdfaf%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/172d405e556e2f1204be126bb3eb28c5115af91bcc1651b4e870bb82%40%3Cdev.tomee.apache.org%3E
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://github.com/quartz-scheduler/quartz/issues/467
- https://lists.apache.org/thread.html/re9b56ac1934d7bf16afc83eac1c39c98c1b20b4b15891dce923bf8aa%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r3a6884e8d819f32cde8c07b98934de3e80467859880f784950bf44cf%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r21df13c8bd2c2eae4b9661aae814c4a2a814d1f7875c765b8b115c9a%40%3Ccommits.tomee.apache.org%3E
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://security.netapp.com/advisory/ntap-20221028-0002/
- https://confluence.atlassian.com/security/ssot-117-cve-2019-13990-xxe-xml-external-entity-injection-vulnerability-in-jira-service-management-data-center-and-jira-service-management-server-1295385959.html
More from softwareag
View All →CVE-2021-40650
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued...
Medium
6.5
CVE-2021-40649
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued...
Medium
6.5
CVE-2021-33581
MashZone NextGen through 10.7 GA has an SSRF vulnerability that...
High
7.2
CVE-2021-33523
MashZone NextGen through 10.7 GA allows a remote authenticated user,...
High
7.2
CVE-2021-33208
The "Register an Ehcache Configuration File" admin feature in MashZone...
High
7.2
Affected Vendor
softwareag
View all reports →Affected Software
quartz, apache batik mapviewer, banking enterprise originations, banking enterprise product manufacturing, banking payments, communications ip service activator, communications session route manager, customer management and segmentation foundation, documaker, enterprise manager base platform, enterprise manager ops center, flexcube investor servicing, flexcube private banking, fusion middleware mapviewer, google guava mapviewer, hyperion infrastructure technology, jd edwards enterpriseone orchestrator, primavera unifier, retail back office, retail central office, retail integration bus, retail order broker, retail point-of-service, retail returns management, retail xstore point of service, terracotta quartz scheduler mapviewer, webcenter sites, tomee, active iq unified manager, cloud secure agent, jira service management
Vulnerable Versions:
0, 12.2.0.1, 18c, 19c, 2.7.0, 2.8.0, 14.1.0, 7.3.0, 7.4.0, 8.2.0, 18.0, 12.6.0, 13.2.1.0, 12.4.0.0, 12.1.0, 12.3.0, 12.4.0, 14.4.0, 12.0.0, 12.2.1.3.0, 11.1.2.4, 17.7, 16.1, 16.2, 18.8, 14.1, 15.0, 16.0, 19.0, 17.0, 12.2.1.4.0, 7.1.3, 4.20.0, 4.20.1, 4.20.2, 4.20.3, 4.20.4, 4.20.5, 4.20.6, 4.20.7, 4.20.8, 4.20.9, 4.20.10, 4.20.11, 4.20.12, 4.20.13, 4.20.14, 4.20.15, 4.20.16, 4.20.17, 4.20.18, 4.20.19, 4.20.20, 4.20.21, 4.20.22, 4.20.23, 4.20.24, 4.20.25, 4.21.0, 4.21.1, 4.22.0, 4.22.1, 4.22.2, 4.22.3, 4.22.4, 4.22.6, 5.0.0, 5.1.0, 5.1.1, 5.2.0, 5.2.1, 5.3.0, 5.3.1, 5.3.2, 5.3.3, 5.4.0, 5.4.1, 5.4.2, 5.4.3, 5.4.4, 5.4.5, 5.4.6, 5.4.7, 5.4.8, 5.4.9, 5.5.1, 5.6.0, 5.7.0, 5.7.1, 5.8.0, 5.8.1, 5.9.0, 5.10.0
Timeline
Official Publish:
July 26th, 2019
Last Modified:
October 15th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.