Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8075
HistoryDec 26, 2018 - 1:56 a.m.

XML External Entity (XXE)

2018-12-2601:56:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.023

Percentile

89.8%

c3p0 is vulnerable to XML external entity (XXE) attacks. The external entity expansion is not disabled in the XML parser, which would allow a remote attacker to perform XXE attacks via a crafted XML document. This CVE is also known as CVE-2019-5427.