Feedback
Did this article resolve your question/issue?

   

Article

Vulnerabilities detected in XQuery with embeded Axis-1.4 component. CVE-2012-5784, CVE-2014-3596, CVE-2018-8032

Information

 
TitleVulnerabilities detected in XQuery with embeded Axis-1.4 component. CVE-2012-5784, CVE-2014-3596, CVE-2018-8032
URL Namevulnerabilities-detected-in-xquery-with-embeded-axis-1-4-component-cve-2012-5784-cve-2014-3596-cve-2018-8032
Article Number000110357
EnvironmentProduct: XQuery
Version: 5.0
O/S: All Supported
Database: N/A
Application: N/A
Question/Problem Description
Vulnerabilities detected in XQuery with embeded Axis-1.4 component. 

Three MEDIUM CVEs apply for ddxqaxis 5.0 => CVE-2012-5784, CVE-2014-3596, CVE-2018-8032.  

This jar embeds Axis-1.4 and so gets flagged for these vulnerabilities.  

Inspection of ddxq.jar reveals usage of this jar:

$ find ddxq EDI XMLConverters xqjapi xquerywebservice -name '*.jar' -exec zipgrep 'com.ddtek.xquery.axis' '{}' \; 2>&1 | tee /tmp/zg
com/ddtek/xquery/mediator/plan/HTTPResponse.class:Binary file (standard input) matches
com/ddtek/xquery/mediator/plan/HTTPContext.class:Binary file (standard input) matches
com/ddtek/xquery/mediator/plan/HTTPClient.class:Binary file (standard input) matches
com/ddtek/xquery/mediator/plan/HTTPClient$AuthCredentialsProvider.class:Binary file (standard input) matches
com/ddtek/xquery/mediator/xtuple/DDXQBuiltInFunctions$WSCallHTTPProperties.class:Binary file (standard input) matches
com/ddtek/xquery/mediator/xtuple/DDXQBuiltInFunctions.class:Binary file (standard input) matches

How will this be addressed by Progress?
Steps to Reproduce
Clarifying Information
Error Message
Defect Number
Enhancement Number
Cause
Resolution
Progress plans to release an update that addresses these CVEs in May 2019
Workaround
Notes
Last Modified Date2/20/2019 6:08 PM
Files
Disclaimer The origins of the information on this site may be internal or external to Progress Software Corporation (“Progress”). Progress Software Corporation makes all reasonable efforts to verify this information. However, the information provided is for your information only. Progress Software Corporation makes no explicit or implied claims to the validity of this information.

Any sample code provided on this site is not supported under any Progress support program or service. The sample code is provided on an "AS IS" basis. Progress makes no warranties, express or implied, and disclaims all implied warranties including, without limitation, the implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample code is borne by the user. In no event shall Progress, its employees, or anyone else involved in the creation, production, or delivery of the code be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample code, even if Progress has been advised of the possibility of such damages.