CVE-2015-3192
published 2016-07-12CVE-2015-3192: Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows…
PriorityP421medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
2.56%
83.3th percentile
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 4.1.9-1 (bookworm) | libspring-java 4.1.9-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| pivotal_software | spring_framework | — | — |
| pivotal_software | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Spring Framework vulnerabilities
vendor_ubuntu·2021-03-17·CVSS 8.8
CVE-2015-5211 [HIGH] Spring Framework vulnerabilities
Title: Spring Framework vulnerabilities
Summary: Several security issues were fixed in Spring Framework.
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this is
Red Hat
Framework: denial-of-service attack with XML input
vendor_redhat·2015-06-30·CVSS 5.5
CVE-2015-3192 [MEDIUM] CWE-20 Framework: denial-of-service attack with XML input
Framework: denial-of-service attack with XML input
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
A denial of service flaw was found in the way Spring processes inline DTD declarations. A remote attacker could submit a specially crafted XML file that would cause out-of-memory errors when parsed.
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Under investigation
Package: rhevm-dependencies (Red Hat Enterprise Virtualization 3) - Under investigation
Package: springframework (Red Hat JBoss BRMS 5) - Will not fix
Package: springframework (R
Debian
CVE-2015-3192: libspring-java - Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly proc...
vendor_debian·2015·CVSS 5.5
CVE-2015-3192 [MEDIUM] CVE-2015-3192: libspring-java - Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly proc...
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
Scope: local
bookworm: resolved (fixed in 4.1.9-1)
bullseye: resolved (fixed in 4.1.9-1)
forky: resolved (fixed in 4.1.9-1)
sid: resolved (fixed in 4.1.9-1)
trixie: resolved (fixed in 4.1.9-1)
OSV
libspring-java vulnerabilities
osv·2021-03-17·CVSS 8.8
CVE-2015-3192 [HIGH] libspring-java vulnerabilities
libspring-java vulnerabilities
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of ser
GHSA
Pivotal Spring Framework DoS Attack with XML Input
ghsa·2018-10-17
CVE-2015-3192 [MEDIUM] CWE-119 Pivotal Spring Framework DoS Attack with XML Input
Pivotal Spring Framework DoS Attack with XML Input
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
OSV
Pivotal Spring Framework DoS Attack with XML Input
osv·2018-10-17
CVE-2015-3192 [MEDIUM] Pivotal Spring Framework DoS Attack with XML Input
Pivotal Spring Framework DoS Attack with XML Input
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
OSV
CVE-2015-3192: Pivotal Spring Framework before 3
osv·2016-07-12·CVSS 5.5
CVE-2015-3192 [MEDIUM] CVE-2015-3192: Pivotal Spring Framework before 3
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3192 Spring Framework: denial-of-service attack with XML input
bugzilla·2015-07-03·CVSS 5.5
CVE-2015-3192 [MEDIUM] CVE-2015-3192 Spring Framework: denial-of-service attack with XML input
CVE-2015-3192 Spring Framework: denial-of-service attack with XML input
The following flaw was found in all versions of Spring Framework:
If DTD is not entirely disabled, inline DTD declarations can be used to perform denial of service attacks known as XML bombs. Such declarations are both well-formed and valid according to XML schema rules but when parsed can cause out of memory errors. To protect against this kind of attack DTD support must be disabled by setting the disallow-doctype-dec feature in the DOM and SAX APIs to true and by setting the supportDTD property in the StAX API to false.
Upstream bug:
https://jira.spring.io/browse/SPR-13136
External References:
http://pivotal.io/security/cve-2015-3192
Discussion:
Created springframework tracking bugs for this issue:
Affects:
Bugzilla
CVE-2015-3192 springframework: Spring Framework: denial-of-service attack with XML input [fedora-all]
bugzilla·2015-07-03·CVSS 5.5
CVE-2015-3192 [MEDIUM] CVE-2015-3192 springframework: Spring Framework: denial-of-service attack with XML input [fedora-all]
CVE-2015-3192 springframework: Spring Framework: denial-of-service attack with XML input [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162015.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/162017.htmlhttp://pivotal.io/security/cve-2015-3192http://rhn.redhat.com/errata/RHSA-2016-1592.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1593.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2036.htmlhttp://www.securityfocus.com/bid/90853http://www.securitytracker.com/id/1036587https://access.redhat.com/errata/RHSA-2016:1218https://access.redhat.com/errata/RHSA-2016:1219https://jira.spring.io/browse/SPR-13136https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/162015.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/162017.htmlhttp://pivotal.io/security/cve-2015-3192http://rhn.redhat.com/errata/RHSA-2016-1592.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1593.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2036.htmlhttp://www.securityfocus.com/bid/90853http://www.securitytracker.com/id/1036587https://access.redhat.com/errata/RHSA-2016:1218https://access.redhat.com/errata/RHSA-2016:1219https://jira.spring.io/browse/SPR-13136https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
2016-07-12
Published