Lucene search

K
cveApacheCVE-2019-12400
HistoryAug 23, 2019 - 9:15 p.m.

CVE-2019-12400

2019-08-2321:15:11
CWE-20
apache
web.nvd.nist.gov
172
2
cve
2019
12400
apache
santuario
xml security
java
cache pollution
security flaws

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

58.2%

In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.

Affected configurations

Nvd
Node
apachesantuario_xml_security_for_javaRange2.0.32.0.10
OR
apachesantuario_xml_security_for_javaRange2.1.02.1.4
Node
redhatjboss_enterprise_application_platformMatch7.2
Node
oracleweblogic_serverMatch12.2.1.4.0
OR
oracleweblogic_serverMatch14.1.1.0.0
VendorProductVersionCPE
apachesantuario_xml_security_for_java*cpe:2.3:a:apache:santuario_xml_security_for_java:*:*:*:*:*:*:*:*
redhatjboss_enterprise_application_platform7.2cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*
oracleweblogic_server12.2.1.4.0cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
oracleweblogic_server14.1.1.0.0cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Apache Santuario - XML Security for Java",
    "vendor": "Apache",
    "versions": [
      {
        "status": "affected",
        "version": "All 2.0.x releases from 2.0.3"
      },
      {
        "status": "affected",
        "version": "all 2.1.x releases before 2.1.4."
      }
    ]
  }
]

References

Social References

More

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

58.2%