initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Tomee
APPApache7.1.3Atlassian Jira Service Management
APPAtlassian4.20.04.20.14.20.104.20.114.20.124.20.134.20.144.20.154.20.164.20.174.20.184.20.194.20.24.20.204.20.21+ 29 moreNetapp Active Iq Unified Manager
APPNetappall versionsNetapp Cloud Secure Agent
APPNetappall versionsOracle Apache Batik Mapviewer
APPOracle12.2.0.118c19cOracle Banking Enterprise Originations
APPOracle2.7.02.8.0Oracle Banking Enterprise Product Manufacturing
APPOracle2.7.02.8.0Oracle Banking Payments
APPOracle14.1.0 – 14.4.0Oracle Communications Ip Service Activator
APPOracle7.3.07.4.0Oracle Communications Session Route Manager
APPOracle8.2.0 – 8.2.2Oracle Customer Management And Segmentation Foundation
APPOracle18.0Oracle Documaker
APPOracle12.6.0 – 12.6.4Oracle Enterprise Manager Base Platform
APPOracle13.2.1.0Oracle Enterprise Manager Ops Center
APPOracle12.4.0.0Oracle Flexcube Investor Servicing
APPOracle12.1.012.3.012.4.014.1.014.4.0Oracle Flexcube Private Banking
APPOracle12.0.012.1.0Oracle Fusion Middleware Mapviewer
APPOracle12.2.1.3.0Oracle Google Guava Mapviewer
APPOracle12.2.0.118c19cOracle Hyperion Infrastructure Technology
APPOracle11.1.2.4Oracle Jd Edwards Enterpriseone Orchestrator
APPOracle≤ 9.2.5.3Oracle Primavera Unifier
APPOracle16.116.218.817.7 – 17.12Oracle Retail Back Office
APPOracle14.1Oracle Retail Central Office
APPOracle14.1Oracle Retail Integration Bus
APPOracle15.016.0Oracle Retail Order Broker
APPOracle15.016.018.019.0Oracle Retail Point Of Service
APPOracle14.1Oracle Retail Returns Management
APPOracle14.1Oracle Retail Xstore Point Of Service
APPOracle15.016.017.018.019.0Oracle Terracotta Quartz Scheduler Mapviewer
APPOracle12.2.0.118c19cOracle Webcenter Sites
APPOracle12.2.1.3.012.2.1.4.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XXE
References
Related vulnerabilities
CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓same product
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2026-62457CRITICAL9.8same product
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common E...