xmltooling: XML parser class fails to trap exceptions on malformed XML declaration
Published Apr 11, 2019
7.5
HIGHCVSS 3.1
EPSS 2.05%
Description
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.
Affected products
No data.
Configuration 1
- < 3.0.4
Configuration 2
- 14.04
- 16.04
- 18.04
- 18.10
No data.
Red Hat JBoss Data Grid 6
xmltooling
Out of support scope
Red Hat JBoss Data Virtualization 6
xmltooling
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
xmltooling
Out of support scope
Red Hat JBoss Fuse 6
xmltooling
Out of support scope
Red Hat JBoss Fuse Service Works 6
xmltooling
Out of support scope
Red Hat JBoss Operations Network 3
XMLTooling
Out of support scope
Red Hat JBoss Portal 6
xmltooling
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Data Grid 6 | xmltooling | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | xmltooling | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | xmltooling | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | xmltooling | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | xmltooling | Out of support scope | n/a |
| Red Hat JBoss Operations Network 3 | XMLTooling | Out of support scope | n/a |
| Red Hat JBoss Portal 6 | xmltooling | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.05% (0.02052) | 80.55th | v5 (v2026.06.15) |
| Sep 20, 2026 | 2.05% (0.02052) | 80.39th | v5 (v2026.06.15) |
| Jul 20, 2024 | 2.61% (0.02606) | 90.44th | v3 (v2023.03.01) |
| Apr 4, 2024 | 2.61% (0.02606) | 90.09th | v3 (v2023.03.01) |
| Sep 3, 2023 | 1.72% (0.01716) | 86.27th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.53% (0.01526) | 84.97th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 14.86% (0.14862) | 91.25th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.04% (0.07038) | 83.71th | v1 |
| Jan 6, 2022 | 7.04% (0.07038) | 83.55th | v1 |
| Jan 5, 2022 | 1.66% (0.01659) | 74.85th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.66% (0.01659) | 0.00th | v1 |
References (11)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00079.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00095.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-9628 Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/xmltooling/+bug/1819912 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1695997 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-9628
- https://security.netapp.com/advisory/ntap-20190611-0003/ x_refsource_CONFIRMThird Party Advisory
- https://shibboleth.net/community/advisories/secadv_20190311.txt x_refsource_MISCThird Party Advisory
- https://usn.ubuntu.com/3921-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://wiki.shibboleth.net/confluence/display/SP3/SecurityAdvisories x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9628
Change history (0)
No recorded changes yet.