7.5
CVSSv3

CVE-2019-5427

Published: 22/04/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mchange c3p0

fedoraproject fedora 29

fedoraproject fedora 30

oracle retail xstore point of service 15.0

oracle flexcube private banking 12.1.0

oracle flexcube private banking 12.0.0

oracle webcenter sites 12.2.1.3.0

oracle retail xstore point of service 16.0

oracle webcenter sites 12.2.1.4.0

oracle retail xstore point of service 17.0

oracle retail xstore point of service 18.0

oracle retail xstore point of service 19.0

oracle communications ip service activator 7.4.0

oracle communications ip service activator 7.3.0

oracle hyperion infrastructure technology 11.1.2.4

oracle enterprise manager ops center 12.4.0.0

oracle communications session route manager

oracle enterprise manager base platform 13.2.1.0

oracle documaker

Vendor Advisories

Synopsis Important: Red Hat Fuse 760 security update Type/Severity Security Advisory: Important Topic A minor version update (from 75 to 76) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security h ...
Debian Bug report logs - #927936 c3p0: CVE-2019-5427 Package: src:c3p0; Maintainer for src:c3p0 is Debian Java Maintainers &lt;pkg-java-maintainers@listsaliothdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Thu, 25 Apr 2019 07:21:02 UTC Severity: important Tags: security, upstream Found in ve ...
Impact: Moderate Public Date: 2019-04-17 CWE: CWE-776 Bugzilla: 1709860: CVE-2019-5427 c3p0: loading XM ...