XML External Entity injection in Apache Camel - CVE-2019-0188
Published: May 22, 2019
Vulnerability identifier: #VU18570
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0188
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform XXE attacks.
The vulnerability exists due to usage of a third-party JSON-lib library vulnerable to XML external entity injection attacks. A remote attacker can send a specially crafted request to the affected application and read contents of arbitrary file on the system.
Affected software
Apache Camel
Jazz for Service Management
Oracle FLEXCUBE Private Banking
Oracle Enterprise Repository
Jazz for Service Management
Oracle FLEXCUBE Private Banking
Oracle Enterprise Repository
How to mitigate CVE-2019-0188
Install updates from vendor's website.
Apache Camel - update to 2.24.0
Jazz for Service Management - update to 1.1.3.25
Jazz for Service Management - update to 1.1.3.25