cbcvebase.
CVE-2014-0225
published 2017-05-25

CVE-2014-0225: When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by…

PriorityP340high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.70%
74.6th percentile
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibspring-java< libspring-java 3.0.6.RELEASE-14 (bookworm)libspring-java 3.0.6.RELEASE-14 (bookworm)
pivotalspring_framework
pivotalspring_framework
pivotalspring_framework
pivotal_softwarespring_framework
pivotal_softwarespring_framework
pivotal_softwarespring_framework
pivotal_softwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.