XML External Entity Reference in Apache Santuario XML Security for Java - CVE-2019-12400
Published: August 26, 2019 / Updated: August 27, 2019
Vulnerability identifier: #VU20401
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12400
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to the loading of XML parsing code from an untrusted source. A remote attacker can exploit this vulnerability to launch further attacks on the system when validating signed documents.
Affected software
Apache Santuario XML Security for Java
JBoss Enterprise Application Platform
Oracle WebLogic Server
Red Hat Single Sign-On
JBoss Enterprise Application Platform
Oracle WebLogic Server
Red Hat Single Sign-On
How to mitigate CVE-2019-12400
Install updates from vendor's website.
Apache Santuario XML Security for Java - update to 2.1.4
JBoss Enterprise Application Platform - update to 7.2.7
Red Hat Single Sign-On - update to 7.3.7
JBoss Enterprise Application Platform - update to 7.2.7
Red Hat Single Sign-On - update to 7.3.7