CVE-2019-13990
—CVSS 3.1
9.8 critical
EPSS
16%p97
Published
()
Modified
Description
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
- Vendors
- softwareagoracleapachenetappatlassian
- Products
- quartz, apache batik mapviewer, banking enterprise originations, banking enterprise product manufacturing, banking payments, communications ip service activator, communications session route manager, customer management and segmentation foundation, documaker, enterprise manager base platform, enterprise manager ops center, flexcube investor servicing
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.