ZeroHour

CVE-2019-5427

PoC
CVSS 3.1
7.5 high
EPSS
5%p92
Published
()
Modified
Description

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Vendors
mchangefedoraprojectoracle
Products
c3p0, fedora, communications ip service activator, communications session route manager, documaker, enterprise manager base platform, enterprise manager ops center, flexcube private banking, hyperion infrastructure technology, retail xstore point of service, webcenter sites
Weakness
CWE-776
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.