peter bassill · operator
$ cve CVE-2019-13990 JSON

CVE-2019-13990

9.8
CRITICAL · CVSS 3.1 · EPSS 16.2% (pctl 97)

Patch early

EPSS 16.2% — above the 10% action threshold.

Description

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS16.2% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploitnone known
Published2019-07-26
Last modified2026-06-17

Affected (31)

VendorProduct
apachetomee
atlassianjira service management
netappactive iq unified manager
netappcloud secure agent
oracleapache batik mapviewer
oraclebanking enterprise originations
oraclebanking enterprise product manufacturing
oraclebanking payments
oraclecommunications ip service activator
oraclecommunications session route manager
oraclecustomer management and segmentation foundation
oracledocumaker
oracleenterprise manager base platform
oracleenterprise manager ops center
oracleflexcube investor servicing
oracleflexcube private banking
oraclefusion middleware mapviewer
oraclegoogle guava mapviewer
oraclehyperion infrastructure technology
oraclejd edwards enterpriseone orchestrator
oracleprimavera unifier
oracleretail back office
oracleretail central office
oracleretail integration bus
oracleretail order broker
oracleretail point-of-service
oracleretail returns management
oracleretail xstore point of service
oracleterracotta quartz scheduler mapviewer
oraclewebcenter sites
softwareagquartz

References

→ the Explorer  ·  watch your stack  ·  NVD