CVE-2018-20433

Related Vulnerabilities: CVE-2018-20433  

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

The MITRE CVE dictionary describes this issue as:

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

Find out more about CVE-2018-20433 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.3
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 c3p0 Under investigation
Red Hat Satellite 6 c3p0 Under investigation
Red Hat Satellite 5 c3p0 Under investigation
Red Hat OpenStack Platform 14 opendaylight Affected
Red Hat OpenStack Platform 13.0 (Queens) opendaylight Affected
Red Hat OpenShift Application Runtimes 1.0 vertx Under investigation
Red Hat Mobile Application Platform On-Premise 4 millicore Under investigation
Red Hat JBoss Web Server 5 c3p0 Under investigation
Red Hat JBoss Web Server 3 c3p0 Under investigation
Red Hat JBoss Fuse 7 c3p0 Under investigation
Red Hat JBoss Fuse 6 c3p0 Under investigation
Red Hat JBoss Enterprise SOA Platform 5 c3p0 Under investigation
Red Hat JBoss EWS 2 c3p0 Under investigation
Red Hat JBoss EAP 5 c3p0 Under investigation
Red Hat JBoss Data Virtualization 6 c3p0 Under investigation
Red Hat JBoss Data Grid 7 c3p0 Under investigation
Red Hat JBoss BRMS 5 c3p0 Under investigation
Red Hat JBoss BPMS 6 c3p0 Under investigation
Red Hat Gluster Storage 3 rhevm-dependencies Affected