Vulnerability Name: CVE-2019-0188 (CCN-161424) Assigned: 2018-11-14 Published: 2019-05-22 Updated: 2021-03-15 Summary: Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed. CVSS v3 Severity: 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N )6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): NoneAvailibility (A): None
5.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N )5.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
Vulnerability Type: CWE-611 Vulnerability Consequences: Obtain Information References: Source: MITRE Type: CNACVE-2019-0188 Source: CCN Type: JVN#71498764Apache Camel vulnerable to XML external entity injection (XXE) Source: JVN Type: Third Party Advisory, VDB EntryJVN#71498764 Source: MLIST Type: Mailing List, Third Party Advisory[oss-security] 20190524 [SECURITY][ERRATA-CORRIGE] New security advisory CVE-2019-0188 released for Apache Camel Source: CCN Type: Oracle CPUOct2019Oracle Critical Patch Update Advisory - October 2019 Source: BID Type: Third Party Advisory, VDB Entry108422 Source: CCN Type: Apache Camel Web siteApache Camel Source: XF Type: UNKNOWNapache-cve20190188-info-disc(161424) Source: CONFIRM Type: Broken Linkhttps://github.com/apache/camel/blob/master/docs/user-manual/en/security-advisories/CVE-2019-0188.txt.asc Source: MLIST Type: Mailing List, Vendor Advisory[camel-users] 20190524 [SECURITY][ERRATA-CORRIGE] New security advisory CVE-2019-0188 released for Apache Camel Source: MLIST Type: Mailing List, Vendor Advisory[tamaya-dev] 20190607 [jira] [Created] (TAMAYA-410) Update camel-core dependency past CVE-2019-0188 Source: MLIST Type: Mailing List, Vendor Advisory[tamaya-commits] 20190607 [incubator-tamaya-sandbox] branch master updated: TAMAYA-410 bump camel-core version past CVE-2019-0188 Source: MLIST Type: Mailing List, Vendor Advisory[tamaya-commits] 20190607 [GitHub] [incubator-tamaya-sandbox] peculater merged pull request #30: TAMAYA-410 bump camel-core version past CVE-2019-0188 Source: MLIST Type: Mailing List, Vendor Advisory[tamaya-commits] 20190607 [GitHub] [incubator-tamaya-sandbox] ottlinger commented on issue #30: TAMAYA-410 bump camel-core version past CVE-2019-0188 Source: MLIST Type: Mailing List, Vendor Advisory[tamaya-commits] 20190607 [GitHub] [incubator-tamaya-sandbox] peculater opened a new pull request #30: TAMAYA-410 bump camel-core version past CVE-2019-0188 Source: MLIST Type: Mailing List, Vendor Advisory[activemq-issues] 20190723 [jira] [Created] (AMQ-7249) Security Vulnerabilities in the ActiveMQ dependent jars. Source: MLIST Type: Mailing List, Vendor Advisory[tamaya-dev] 20190607 [jira] [Commented] (TAMAYA-410) Update camel-core dependency past CVE-2019-0188 Source: MLIST Type: Mailing List, Vendor Advisory[tamaya-dev] 20190607 [jira] [Closed] (TAMAYA-410) Update camel-core dependency past CVE-2019-0188 Source: CCN Type: IBM Security Bulletin 6340097 (Resilient OnPrem)IBM Resilient SOAR is Using Components with Known Vulnerabilities - Apache Camel ( CVE-2019-0188, CVE-2020-11972, CVE-2020-11973) Source: MISC Type: Third Party Advisoryhttps://www.oracle.com/security-alerts/cpujan2021.html Source: CCN Type: Oracle CPUJul2020Oracle Critical Patch Update Advisory - July 2020 Source: MISC Type: Third Party Advisoryhttps://www.oracle.com/security-alerts/cpujul2020.html Source: MISC Type: Third Party Advisoryhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2019-0188 Vulnerable Configuration: Configuration 1 :cpe:/a:apache:camel:*:*:*:*:*:*:*:* (Version < 2.24.0)OR cpe:/a:oracle:enterprise_data_quality:11.1.1.9.0:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_base_platform:13.3.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:* Configuration 2 :cpe:/a:oracle:enterprise_repository:12.1.3.0.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:apache:camel:2.23.0:*:*:*:*:*:*:* AND cpe:/a:oracle:flexcube_private_banking:12.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_private_banking:12.1:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_repository:12.1.3.0.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
apache camel *
oracle enterprise data quality 11.1.1.9.0
oracle enterprise manager base platform 13.3.0.0
oracle enterprise manager base platform 13.4.0.0
oracle flexcube private banking 12.0.0
oracle flexcube private banking 12.1.0
oracle enterprise repository 12.1.3.0.0
apache camel 2.23.0
oracle flexcube private banking 12.0
oracle flexcube private banking 12.1
oracle enterprise repository 12.1.3.0.0