Description
Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files from application hosts that read cached query results, including stored database and IAM role credentials, via crafted XML data in a cached column value.



To remediate this issue, users should upgrade to version 4.3.0 or later.
Published: 2026-09-11
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure
Action: Upgrade Now
AI Analysis

Impact

The RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 fails to restrict processing of XML external entity references. An actor with write access to the shared cache infrastructure can insert crafted XML into a cached column value. The plugin then processes this XML, causing the underlying XML parser to access and read files on the application host, including stored database and IAM role credentials. The result is an unauthorized disclosure of sensitive files and credentials. This vulnerability represents a confidentiality breach rather than code execution.

Affected Systems

AWS Advanced JDBC Wrapper, versions 3.3.0 to 4.2.0, distributed by Amazon Web Services. All deployments using these versions of the Advanced JDBC Wrapper susceptible.

Risk and Exploitability

The CVSS score of 6 indicates a moderate severity. EPSS data is not available, so the current probability of exploitation is unknown, but the vulnerability is only exploitable when an attacker can write to the cache. Since this requires elevated write permissions, the potential attack vector is internal or compromised, making it less likely in a well‑segmented environment. The vulnerability is not listed in the CISA KEV catalog, which further reduces the perceived threat. Nonetheless, an attacker who gains the necessary cache access can obtain critical credentials directly from the host filesystem.

Generated by OpenCVE AI on September 11, 2026 at 17:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the AWS Advanced JDBC Wrapper to version 4.3.0 or later.
  • Limit write permissions on the shared cache infrastructure to the minimum set of trusted users or services.
  • Disable or restrict XML external entity processing in any XML parsers used by the application that handle cached data.
  • Continuously monitor the cache for unexpected content and audit write operations to detect potential abuse.

Generated by OpenCVE AI on September 11, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Amazon
Amazon advanced Jdbc Wrapper
CPEs cpe:2.3:a:amazon:advanced_jdbc_wrapper:*:*:*:*:*:*:*:*
Vendors & Products Amazon
Amazon advanced Jdbc Wrapper

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files from application hosts that read cached query results, including stored database and IAM role credentials, via crafted XML data in a cached column value. To remediate this issue, users should upgrade to version 4.3.0 or later.
Title Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
First Time appeared Aws
Aws aws Advanced Jdbc Wrapper
Weaknesses CWE-611
CPEs cpe:2.3:a:aws:aws_advanced_jdbc_wrapper:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws aws Advanced Jdbc Wrapper
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Amazon Advanced Jdbc Wrapper
Aws Aws Advanced Jdbc Wrapper
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-11T19:19:15.260Z

Reserved: 2026-07-28T13:59:19.962Z

Link: CVE-2026-18061

cve-icon Vulnrichment

Updated: 2026-09-11T19:19:11.410Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T17:17:08.927

Modified: 2026-09-16T14:03:36.323

Link: CVE-2026-18061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:15:14Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference