CVE Vulnerabilities

CVE-2019-9628

Improper Handling of Exceptional Conditions

Published: Apr 11, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
XmltoolingXmltooling_project*3.0.4 (excluding)
XmltoolingUbuntubionic*
XmltoolingUbuntucosmic*
XmltoolingUbuntudevel*
XmltoolingUbuntuesm-apps/bionic*
XmltoolingUbuntuesm-apps/xenial*
XmltoolingUbuntuesm-infra-legacy/trusty*
XmltoolingUbuntutrusty*
XmltoolingUbuntutrusty/esm*
XmltoolingUbuntuupstream*
XmltoolingUbuntuxenial*

References