XML External Entity injection in Apache Camel - CVE-2019-0188

 

XML External Entity injection in Apache Camel - CVE-2019-0188

Published: May 22, 2019


Vulnerability identifier: #VU18570
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0188
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform XXE attacks.

The vulnerability exists due to usage of a third-party JSON-lib library vulnerable to XML external entity injection attacks. A remote attacker can send a specially crafted request to the affected application and read contents of arbitrary file on the system.



Affected software

Apache Camel
Jazz for Service Management
Oracle FLEXCUBE Private Banking
Oracle Enterprise Repository

How to mitigate CVE-2019-0188

Install updates from vendor's website.

Apache Camel - update to 2.24.0
Jazz for Service Management - update to 1.1.3.25

External References

Related Security Bulletins