cbcvebase.
CVE-2019-3773
published 2019-01-18

CVE-2019-3773: Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when…

PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.11%
89.6th percentile
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Affected

7 ranges
VendorProductVersion rangeFixed in
oraclefinancial_services_analytical_applications_infrastructure8.0.6 – 8.1.0
oracleflexcube_private_banking
oracleflexcube_private_banking
pivotal_softwarespring_web_services<= 2.4.3
pivotal_softwarespring_web_services3.0.0 – 3.0.4
springspring_web_services>= 2.4 < v2.4.3.RELEASEv2.4.3.RELEASE
springspring_web_services>= 3.0 < v3.0.4.RELEASEv3.0.4.RELEASE

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.