CVE Feed

    Dashboard / CVE / CVE-2019-5427

    CVE-2019-5427

    c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

    Published:Apr 17, 2019
    Last Modified:Sep 5, 2025
    EPS:Apr 22, 2019
    EPSS Score:0.06909
    CVSS Score:7.5

    Affected Products

    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Mchange
    Product
    C3p0
    Vendor
    Oracle
    Product
    Communications Ip Service Activator
    Vendor
    Oracle
    Product
    Communications Session Route Manager
    Vendor
    Oracle
    Product
    Documaker
    Vendor
    Oracle
    Product
    Enterprise Manager Base Platform
    Vendor
    Oracle
    Product
    Enterprise Manager Ops Center
    Vendor
    Oracle
    Product
    Flexcube Private Banking
    Vendor
    Oracle
    Product
    Hyperion Infrastructure Technology
    Vendor
    Oracle
    Product
    Retail Xstore Point Of Service
    Vendor
    Oracle
    Product
    Webcenter Sites
    Vendor
    Redhat
    Product
    Jboss Fuse

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High