Impact
The RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 fails to restrict processing of XML external entity references. An actor with write access to the shared cache infrastructure can insert crafted XML into a cached column value. The plugin then processes this XML, causing the underlying XML parser to access and read files on the application host, including stored database and IAM role credentials. The result is an unauthorized disclosure of sensitive files and credentials. This vulnerability represents a confidentiality breach rather than code execution.
Affected Systems
AWS Advanced JDBC Wrapper, versions 3.3.0 to 4.2.0, distributed by Amazon Web Services. All deployments using these versions of the Advanced JDBC Wrapper susceptible.
Risk and Exploitability
The CVSS score of 6 indicates a moderate severity. EPSS data is not available, so the current probability of exploitation is unknown, but the vulnerability is only exploitable when an attacker can write to the cache. Since this requires elevated write permissions, the potential attack vector is internal or compromised, making it less likely in a well‑segmented environment. The vulnerability is not listed in the CISA KEV catalog, which further reduces the perceived threat. Nonetheless, an attacker who gains the necessary cache access can obtain critical credentials directly from the host filesystem.
OpenCVE Enrichment