XML External Entity injection in jackson-mapper-asl - CVE-2019-10172

 

XML External Entity injection in jackson-mapper-asl - CVE-2019-10172

Published: July 21, 2022 / Updated: April 16, 2025


Vulnerability identifier: #VU65655
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10172
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


Affected software

jackson-mapper-asl
B2B Advanced Communications
IBM Application Suite - IBM Asset Data Dictionary Component
Storage Copy Data Management
Cloudera Observability with IBM
UrbanCode Build
StreamSets Data Collector
CloudLink
Voice Gateway
IBM PureData System for Operational Analytics
IBM Intelligent Operations Center
Confluence Data Center
QRadar User Behavior Analytics
IBM Match 360
IBM UrbanCode Release
IBM Spectrum Protect Plus
Confluence Server
Oracle Commerce Platform
Oracle WebCenter Content
Ubuntu
openEuler
libjackson-json-java (Ubuntu package)
jackson
jackson-help
IBM Cloud Pak System

How to mitigate CVE-2019-10172

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

B2B Advanced Communications - update to 1.0.0.10
Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.18, 1.0.8.24, 1.0.8.29
IBM Intelligent Operations Center - update to 5.2.4
Confluence Data Center - addressed in versions 8.5.21, 9.2.3, 9.4.0
Confluence Server - addressed in versions 8.5.21, 9.2.3, 9.4.0
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.15
libjackson-json-java (Ubuntu package) - update to 1.9.2-7ubuntu0.2
jackson - update to 1.9.11-16
jackson-help - update to 1.9.11-16
Storage Copy Data Management - update to 2.2.26.0
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloudera Observability with IBM - update to 3.6.2
QRadar User Behavior Analytics - update to 4.1.9
IBM Match 360 - update to 4.7.1
UrbanCode Build - update to 6.1.7.10
IBM UrbanCode Release - update to 6.2.5.11
StreamSets Data Collector - update to 7.0.0
CloudLink - update to 8.0-3.10.5.1
IBM Spectrum Protect Plus - update to 10.1.6.4

External References

Related Security Bulletins