ZeroHour

CVE-2019-3772

CVSS 3.0
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Vendors
vmwareoracle
Products
spring integration, retail customer management and segmentation foundation
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.