CVE-2019-5427: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Affected products

  • Fedoraproject Fedora: version 29 only; version 30 only
  • Mchange c3p0: before 0.9.5.4 (fixed in 0.9.5.4)
  • Oracle Communications IP Service Activator: version 7.3.0 only; version 7.4.0 only
  • Oracle Communications Session Route Manager: from 8.2.0, up to and including 8.2.2
  • Oracle Documaker: from 12.6.0, up to and including 12.6.6
  • Oracle Enterprise Manager Base Platform: version 13.2.1.0 only
  • Oracle Enterprise Manager Ops Center: version 12.4.0.0 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
  • Oracle Hyperion Infrastructure Technology: version 11.1.2.4 only
  • Oracle Retail Xstore Point Of Service: version 15.0 only; version 16.0 only; version 17.0 only; version 18.0 only; version 19.0 only
  • Oracle Webcenter Sites: version 12.2.1.3.0 only; version 12.2.1.4.0 only

Published 2019-04-22. Last modified 2026-06-17.