Vulnerability Description
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xmltooling Project | Xmltooling | < 3.0.4 |
| Canonical | Ubuntu Linux | 14.04 |
| Opensuse | Leap | 15.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00079.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00095.htmlMailing ListThird Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/xmltooling/+bug/1819912Issue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190611-0003/Third Party Advisory
- https://shibboleth.net/community/advisories/secadv_20190311.txtThird Party Advisory
- https://usn.ubuntu.com/3921-1/Third Party Advisory
- https://wiki.shibboleth.net/confluence/display/SP3/SecurityAdvisoriesThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00079.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00095.htmlMailing ListThird Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/xmltooling/+bug/1819912Issue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190611-0003/Third Party Advisory
- https://shibboleth.net/community/advisories/secadv_20190311.txtThird Party Advisory
- https://usn.ubuntu.com/3921-1/Third Party Advisory
- https://wiki.shibboleth.net/confluence/display/SP3/SecurityAdvisoriesThird Party Advisory
FAQ
What is CVE-2019-9628?
CVE-2019-9628 is a vulnerability with a CVSS score of 7.5 (HIGH). The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an e...
How severe is CVE-2019-9628?
CVE-2019-9628 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9628?
Check the references section above for vendor advisories and patch information. Affected products include: Xmltooling Project Xmltooling, Canonical Ubuntu Linux, Opensuse Leap.