CVE-2019-3772
published 2019-01-18CVE-2019-3772: Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible…
PriorityP354critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.00%
86.2th percentile
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | retail_customer_management_and_segmentation_foundation | — | — |
| oracle | retail_customer_management_and_segmentation_foundation | — | — |
| oracle | retail_customer_management_and_segmentation_foundation | — | — |
| spring | spring_integration | >= 4.3 < v4.3.18.RELEASE | v4.3.18.RELEASE |
| spring | spring_integration | >= 5.0 < v5.0.10.RELEASE | v5.0.10.RELEASE |
| spring | spring_integration | >= 5.1 < v5.1.1.RELEASE | v5.1.1.RELEASE |
| vmware | spring_integration | <= 4.3.18 | — |
| vmware | spring_integration | 5.0.0 – 5.0.10 | — |
| vmware | spring_integration | 5.1.0 – 5.1.1 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml
ghsa·2019-01-25
CVE-2019-3772 [LOW] CWE-611 Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml
Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
OSV
Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml
osv·2019-01-25
CVE-2019-3772 [LOW] Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml
Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Red Hat
spring-integration: XML External Entity Injection (XXE) when receiving XML data from untrusted sources
vendor_redhat·2019-01-14·CVSS 9.8
CVE-2019-3772 [CRITICAL] CWE-20 spring-integration: XML External Entity Injection (XXE) when receiving XML data from untrusted sources
spring-integration: XML External Entity Injection (XXE) when receiving XML data from untrusted sources
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Package: spring-integration-ws (Red Hat Fuse 7) - Not affected
Package: spring-integration-xml (Red Hat Fuse 7) - Not affected
No detection rules found.
No public exploits indexed.
Tenable
Oracle Critical Patch Update For April Contains 297 Fixes
blogs_tenable·2019-04-17
Oracle Critical Patch Update For April Contains 297 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-3772 spring-integration: XML External Entity Injection (XXE) when receiving XML data from untrusted sources
bugzilla·2019-01-29·CVSS 9.8
CVE-2019-3772 [CRITICAL] CVE-2019-3772 spring-integration: XML External Entity Injection (XXE) when receiving XML data from untrusted sources
CVE-2019-3772 spring-integration: XML External Entity Injection (XXE) when receiving XML data from untrusted sources
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
External References:
https://pivotal.io/security/cve-2019-3772
Discussion:
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-3772
http://www.securityfocus.com/bid/106749https://pivotal.io/security/cve-2019-3772https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://www.securityfocus.com/bid/106749https://pivotal.io/security/cve-2019-3772https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2019-01-18
Published