ZeroHour

CVE-2019-3773

CVSS 3.1
9.8 critical
EPSS
4%p90
Published
()
Modified
Description

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Vendors
broadcomoracle
Products
spring web services, financial services analytical applications infrastructure, flexcube private banking
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.