XML External Entity injection in Quartz Scheduler - CVE-2019-13990

 

XML External Entity injection in Quartz Scheduler - CVE-2019-13990

Published: August 1, 2019 / Updated: November 19, 2019


Vulnerability identifier: #VU19595
CSH Severity: Medium
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13990
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct an XML External Entity (XXE) attack on a targeted system.

The vulnerability exists due to insufficient validation of user-supplied XML input in the "initDocumentParser" function in the "xml/XMLSchedulingDataProcessor.java" file. A remote authenticated attacker can submit a malicious job description to the targeted system and conduct an XXE attack.



Affected software

Quartz Scheduler
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStoreX OS
Oracle Banking Enterprise Originations
Oracle Banking Enterprise Product Manufacturing
Jira Service Management Data Center
Jira Service Management Server
Oracle Communications IP Service Activator
Infrastructure Technology
Enterprise Manager Base Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Communications Session Route Manager
Oracle WebCenter Sites
Oracle Fusion Middleware MapViewer
JD Edwards EnterpriseOne Orchestrator
Identity Manager
Oracle Enterprise Manager Ops Center
Oracle FLEXCUBE Private Banking
Oracle FLEXCUBE Investor Servicing
Oracle Business Intelligence Enterprise Edition
Oracle Retail Back Office
Oracle Retail Returns Management
Oracle Retail Central Office
Oracle Retail Order Broker
PowerStore T
Oracle Database Server
Oracle Internet Directory
Oracle Banking Payments
Oracle Retail Point of Service
Primavera Unifier
IBM Disconnected Log Collector

How to mitigate CVE-2019-13990

Install updates from vendor's website.

Quartz Scheduler - update to 2.3.1
Jira Service Management Data Center - addressed in versions 4.20.26, 5.4.10, 5.7.2, 5.8.2, 5.9.2, 5.10.1
Jira Service Management Server - addressed in versions 4.20.26, 5.4.10, 5.7.2, 5.8.2, 5.9.2, 5.10.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
IBM Disconnected Log Collector - update to 1.6
PowerStoreX OS - update to 3.2.1.6-2476179
PowerStore T - update to 3.5.0.1-2083289

External References

Related Security Bulletins