← לוח פגיעויות

CVE-2019-3773

קריטית 9.8

תיאור (מקור, אנגלית)

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
4% (אחוזון 100) נכון ל-16/9/2026
CWE
CWE-611

מוצרים מושפעים

broadcom: spring web services; oracle: financial services analytical applications infrastructure; oracle: flexcube private banking

קישורים