The XMLTooling library all versions prior to V3.0.4, provided with...
Vulnerability Description
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-9628
Credits & Attribution
No credits recorded in the NVD database.
References
- https://shibboleth.net/community/advisories/secadv_20190311.txt
- https://usn.ubuntu.com/3921-1/
- https://wiki.shibboleth.net/confluence/display/SP3/SecurityAdvisories
- https://bugs.launchpad.net/ubuntu/+source/xmltooling/+bug/1819912
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00079.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00095.html
- https://security.netapp.com/advisory/ntap-20190611-0003/
More from xmltooling project
View All →Affected Vendor
xmltooling project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.