CVE-2019-3773
published 2019-01-18CVE-2019-3773: Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.11%
89.6th percentile
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 – 8.1.0 | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
| pivotal_software | spring_web_services | <= 2.4.3 | — |
| pivotal_software | spring_web_services | 3.0.0 – 3.0.4 | — |
| spring | spring_web_services | >= 2.4 < v2.4.3.RELEASE | v2.4.3.RELEASE |
| spring | spring_web_services | >= 3.0 < v3.0.4.RELEASE | v3.0.4.RELEASE |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
osv·2019-01-25
CVE-2019-3773 [CRITICAL] Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
GHSA
Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
ghsa·2019-01-25
CVE-2019-3773 [CRITICAL] CWE-611 Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Order Management (Spring Web Services) — CVE-2019-3773
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2019-3773 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Order Management (Spring Web Services) — CVE-2019-3773
Oracle Oracle Financial Services Applications Risk Matrix: Order Management (Spring Web Services) vulnerability
CVE: CVE-2019-3773
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Spring Web Services) — CVE-2019-3773
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2019-3773 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Spring Web Services) — CVE-2019-3773
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Spring Web Services) vulnerability
CVE: CVE-2019-3773
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Red Hat
spring-ws: XML External Entity Injection (XXE) when receiving XML data from untrusted sources
vendor_redhat·2019-01-14·CVSS 9.8
CVE-2019-3773 [CRITICAL] CWE-20 spring-ws: XML External Entity Injection (XXE) when receiving XML data from untrusted sources
spring-ws: XML External Entity Injection (XXE) when receiving XML data from untrusted sources
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Package: spring-ws-core (Red Hat JBoss Fuse 6) - Out of support scope
Package: spring-xml (Red Hat JBoss Fuse 6) - Out of support scope
No detection rules found.
No public exploits indexed.
https://pivotal.io/security/cve-2019-3773https://security.netapp.com/advisory/ntap-20231227-0011/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://pivotal.io/security/cve-2019-3773https://security.netapp.com/advisory/ntap-20231227-0011/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.html
2019-01-18
Published