GHSA-9qcf-c26r-x5rf · Severity: critical · Ecosystem: maven — XML external entity injection in Terracotta Quartz Scheduler
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Conclusion & alert: CVE-2019-13990 is rated High Risk (72.5/100): CVSS Critical severity, with high exploitation likelihood (EPSS 13.78%, 94th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-28 | 13.47% | 13.78% | +0.31% |
| 2 | 2026-05-22 | 16.98% | 13.47% | -3.51% |
| 3 | 2026-05-11 | — | 16.98% | — |
Full EPSS history (32 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-9qcf-c26r-x5rf · Severity: critical · Ecosystem: maven — XML external entity injection in Terracotta Quartz Scheduler
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2019-13990 not yet assigned priority: Debian including 2 source packages (libquartz-java, libquartz2-java), 9 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 8, open 1. | https://security-tracker.debian.org/tracker/CVE-2019-13990 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2019-13990 |
suse
|
medium | CVE-2019-13990 severity moderate: SUSE including 233 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 233 product×package rows across 3 product lines (SUSE Manager Server 3.2, SUSE Manager Server Module 4.0, chost): Known Affected 231, Fixed 2. | https://www.suse.com/security/cve/CVE-2019-13990/ |
ubuntu
|
medium | CVE-2019-13990 medium priority: Ubuntu including 2 source packages (libquartz-java, libquartz2-java), 36 status rows across 18 suites (bionic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 12, not-affected 11, needs-triage 10, DNE 3. | https://ubuntu.com/security/CVE-2019-13990 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| softwareag | quartz | < 2.3.2 | cpe:2.3:a:softwareag:quartz:*:*:*:*:*:*:*:* |
| oracle | apache_batik_mapviewer | 12.2.0.1 | cpe:2.3:a:oracle:apache_batik_mapviewer:12.2.0.1:*:*:*:*:*:*:* |
| oracle | apache_batik_mapviewer | 18c | cpe:2.3:a:oracle:apache_batik_mapviewer:18c:*:*:*:*:*:*:* |
| oracle | apache_batik_mapviewer | 19c | cpe:2.3:a:oracle:apache_batik_mapviewer:19c:*:*:*:*:*:*:* |
| oracle | banking_enterprise_originations | 2.7.0 | cpe:2.3:a:oracle:banking_enterprise_originations:2.7.0:*:*:*:*:*:*:* |
| oracle | banking_enterprise_originations | 2.8.0 | cpe:2.3:a:oracle:banking_enterprise_originations:2.8.0:*:*:*:*:*:*:* |
| oracle | banking_enterprise_product_manufacturing | 2.7.0 | cpe:2.3:a:oracle:banking_enterprise_product_manufacturing:2.7.0:*:*:*:*:*:*:* |
| oracle | banking_enterprise_product_manufacturing | 2.8.0 | cpe:2.3:a:oracle:banking_enterprise_product_manufacturing:2.8.0:*:*:*:*:*:*:* |
| oracle | banking_payments | >= 14.1.0, <= 14.4.0 | cpe:2.3:a:oracle:banking_payments:*:*:*:*:*:*:*:* |
| oracle | communications_ip_service_activator | 7.3.0 | cpe:2.3:a:oracle:communications_ip_service_activator:7.3.0:*:*:*:*:*:*:* |
| oracle | communications_ip_service_activator | 7.4.0 | cpe:2.3:a:oracle:communications_ip_service_activator:7.4.0:*:*:*:*:*:*:* |
| oracle | communications_session_route_manager | >= 8.2.0, <= 8.2.2 | cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:* |
| oracle | customer_management_and_segmentation_foundation | 18.0 | cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:* |
| oracle | documaker | >= 12.6.0, <= 12.6.4 | cpe:2.3:a:oracle:documaker:*:*:*:*:*:*:*:* |
| oracle | enterprise_manager_base_platform | 13.2.1.0 | cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.1.0:*:*:*:*:*:*:* |
| oracle | enterprise_manager_ops_center | 12.4.0.0 | cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:* |
| oracle | flexcube_investor_servicing | 12.1.0 | cpe:2.3:a:oracle:flexcube_investor_servicing:12.1.0:*:*:*:*:*:*:* |
| oracle | flexcube_investor_servicing | 12.3.0 | cpe:2.3:a:oracle:flexcube_investor_servicing:12.3.0:*:*:*:*:*:*:* |
| oracle | flexcube_investor_servicing | 12.4.0 | cpe:2.3:a:oracle:flexcube_investor_servicing:12.4.0:*:*:*:*:*:*:* |
| oracle | flexcube_investor_servicing | 14.1.0 | cpe:2.3:a:oracle:flexcube_investor_servicing:14.1.0:*:*:*:*:*:*:* |
| oracle | flexcube_investor_servicing | 14.4.0 | cpe:2.3:a:oracle:flexcube_investor_servicing:14.4.0:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.0.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.1.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:* |
| oracle | fusion_middleware_mapviewer | 12.2.1.3.0 | cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | google_guava_mapviewer | 12.2.0.1 | cpe:2.3:a:oracle:google_guava_mapviewer:12.2.0.1:*:*:*:*:*:*:* |
| oracle | google_guava_mapviewer | 18c | cpe:2.3:a:oracle:google_guava_mapviewer:18c:*:*:*:*:*:*:* |
| oracle | google_guava_mapviewer | 19c | cpe:2.3:a:oracle:google_guava_mapviewer:19c:*:*:*:*:*:*:* |
| oracle | hyperion_infrastructure_technology | 11.1.2.4 | cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_orchestrator | <= 9.2.5.3 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:*:*:*:*:*:*:*:* |
| oracle | primavera_unifier | >= 17.7, <= 17.12 | cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 16.1 | cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 16.2 | cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 18.8 | cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* |
| oracle | retail_back_office | 14.1 | cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:* |
| oracle | retail_central_office | 14.1 | cpe:2.3:a:oracle:retail_central_office:14.1:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 15.0 | cpe:2.3:a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 16.0 | cpe:2.3:a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker | 15.0 | cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker | 16.0 | cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker | 18.0 | cpe:2.3:a:oracle:retail_order_broker:18.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker | 19.0 | cpe:2.3:a:oracle:retail_order_broker:19.0:*:*:*:*:*:*:* |
| oracle | retail_point-of-service | 14.1 | cpe:2.3:a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:* |
| oracle | retail_returns_management | 14.1 | cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 15.0 | cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 16.0 | cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 17.0 | cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 18.0 | cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 19.0 | cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0:*:*:*:*:*:*:* |
| oracle | terracotta_quartz_scheduler_mapviewer | 12.2.0.1 | cpe:2.3:a:oracle:terracotta_quartz_scheduler_mapviewer:12.2.0.1:*:*:*:*:*:*:* |
| oracle | terracotta_quartz_scheduler_mapviewer | 18c | cpe:2.3:a:oracle:terracotta_quartz_scheduler_mapviewer:18c:*:*:*:*:*:*:* |
| oracle | terracotta_quartz_scheduler_mapviewer | 19c | cpe:2.3:a:oracle:terracotta_quartz_scheduler_mapviewer:19c:*:*:*:*:*:*:* |
| oracle | webcenter_sites | 12.2.1.3.0 | cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | webcenter_sites | 12.2.1.4.0 | cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:* |
| apache | tomee | 7.1.3 | cpe:2.3:a:apache:tomee:7.1.3:*:*:*:*:*:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* |
| netapp | cloud_secure_agent | — | cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:* |
| atlassian | jira_service_management | 4.20.0 | cpe:2.3:a:atlassian:jira_service_management:4.20.0:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.0 | cpe:2.3:a:atlassian:jira_service_management:4.20.0:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.1 | cpe:2.3:a:atlassian:jira_service_management:4.20.1:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.1 | cpe:2.3:a:atlassian:jira_service_management:4.20.1:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.2 | cpe:2.3:a:atlassian:jira_service_management:4.20.2:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.2 | cpe:2.3:a:atlassian:jira_service_management:4.20.2:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.3 | cpe:2.3:a:atlassian:jira_service_management:4.20.3:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.3 | cpe:2.3:a:atlassian:jira_service_management:4.20.3:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.4 | cpe:2.3:a:atlassian:jira_service_management:4.20.4:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.4 | cpe:2.3:a:atlassian:jira_service_management:4.20.4:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.5 | cpe:2.3:a:atlassian:jira_service_management:4.20.5:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.5 | cpe:2.3:a:atlassian:jira_service_management:4.20.5:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.6 | cpe:2.3:a:atlassian:jira_service_management:4.20.6:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.6 | cpe:2.3:a:atlassian:jira_service_management:4.20.6:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.7 | cpe:2.3:a:atlassian:jira_service_management:4.20.7:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.7 | cpe:2.3:a:atlassian:jira_service_management:4.20.7:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.8 | cpe:2.3:a:atlassian:jira_service_management:4.20.8:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.8 | cpe:2.3:a:atlassian:jira_service_management:4.20.8:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.9 | cpe:2.3:a:atlassian:jira_service_management:4.20.9:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.9 | cpe:2.3:a:atlassian:jira_service_management:4.20.9:*:*:*:server:*:*:* |
| atlassian | jira_service_management | 4.20.10 | cpe:2.3:a:atlassian:jira_service_management:4.20.10:*:*:*:data_center:*:*:* |
| atlassian | jira_service_management | 4.20.10 | cpe:2.3:a:atlassian:jira_service_management:4.20.10:*:*:*:server:*:*:* |