CVE-2019-5427
HIGHc3p0 <0.9.5.4 - Info Disclosure
Title source: llmDescription
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Exploits (1)
References (8)
Scores
CVSS v3
7.5
EPSS
0.0472
EPSS Percentile
89.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-776
Status
published
Products (20)
com.mchange/c3p0
0 - 0.9.5.4Maven
fedoraproject/fedora
29
fedoraproject/fedora
30
mchange/c3p0
< 0.9.5.4
oracle/communications_ip_service_activator
7.3.0
oracle/communications_ip_service_activator
7.4.0
oracle/communications_session_route_manager
8.2.0 - 8.2.2
oracle/documaker
12.6.0 - 12.6.6
oracle/enterprise_manager_base_platform
13.2.1.0
oracle/enterprise_manager_ops_center
12.4.0.0
... and 10 more
Published
Apr 22, 2019
Tracked Since
Feb 18, 2026