CVE-2019-5427: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Affected products
- Fedoraproject Fedora: version 29 only; version 30 only
- Mchange c3p0: before 0.9.5.4 (fixed in 0.9.5.4)
- Oracle Communications IP Service Activator: version 7.3.0 only; version 7.4.0 only
- Oracle Communications Session Route Manager: from 8.2.0, up to and including 8.2.2
- Oracle Documaker: from 12.6.0, up to and including 12.6.6
- Oracle Enterprise Manager Base Platform: version 13.2.1.0 only
- Oracle Enterprise Manager Ops Center: version 12.4.0.0 only
- Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
- Oracle Hyperion Infrastructure Technology: version 11.1.2.4 only
- Oracle Retail Xstore Point Of Service: version 15.0 only; version 16.0 only; version 17.0 only; version 18.0 only; version 19.0 only
- Oracle Webcenter Sites: version 12.2.1.3.0 only; version 12.2.1.4.0 only
Published 2019-04-22. Last modified 2026-06-17.