SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9628

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class.

HIGH 7.5EPSS 2.05%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
2.05% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-755
Affected
xmltooling project/xmltooling · canonical/ubuntu linux · opensuse/leap
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.