CVE-2019-3773
קריטית 9.8
תיאור (מקור, אנגלית)
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 4% (אחוזון 100) נכון ל-16/9/2026
- CWE
- CWE-611
מוצרים מושפעים
broadcom: spring web services; oracle: financial services analytical applications infrastructure; oracle: flexcube private banking
קישורים
- https://pivotal.io/security/cve-2019-3773 Vendor Advisory
- https://pivotal.io/security/cve-2019-3773 Vendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20231227-0011/
- https://www.oracle.com/security-alerts/cpuApr2021.html Not Applicable
- https://security.netapp.com/advisory/ntap-20231227-0011/
- https://www.oracle.com/security-alerts/cpuApr2021.html Not Applicable