Vmware Spring Framework vulnerabilities
50 known vulnerabilities affecting vmware/spring_framework.
Total CVEs
50
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH17MEDIUM28
Vulnerabilities
Page 3 of 3
CVE-2014-0225HIGHCVSS 8.8v3.0.1v3.0.2+24 more2017-05-25
CVE-2014-0225 [HIGH] CWE-611 CVE-2014-0225: When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, an
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
nvd
CVE-2016-9878HIGHCVSS 7.5v3.2.1v3.2.2+27 more2016-12-29
CVE-2016-9878 [HIGH] CWE-22 CVE-2016-9878: An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x bef
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
nvd
CVE-2015-3192MEDIUMCVSS 5.5v3.2.1v3.2.2+17 more2016-07-12
CVE-2015-3192 [MEDIUM] CWE-119 CVE-2015-3192: Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD decla
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
nvd
CVE-2015-0201MEDIUMCVSS 5.0v4.1.1v4.1.2+2 more2015-03-10
CVE-2015-0201 [MEDIUM] CWE-254 CVE-2015-0201: The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
nvd
CVE-2014-3625MEDIUMCVSS 5.0≥ 3.0.4, ≤ 3.0.72014-11-20
CVE-2014-3625 [MEDIUM] CWE-22 CVE-2014-3625: Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
nvd
CVE-2014-0054MEDIUMCVSS 6.8≤ 3.2.7v3.0.6+12 more2014-04-17
CVE-2014-0054 [MEDIUM] CVE-2014-0054: The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 be
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because o
nvd
CVE-2013-6429MEDIUMCVSS 6.8v4.0.02014-01-26
CVE-2013-6429 [MEDIUM] CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013
nvd
CVE-2013-7315MEDIUMCVSS 6.8≤ 3.2.3v3.0.6+10 more2014-01-23
CVE-2013-7315 [MEDIUM] CVE-2013-7315: The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable exter
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerab
nvd
CVE-2013-4152MEDIUMCVSS 6.8≤ 3.2.3v3.0.6+10 more2014-01-23
CVE-2013-4152 [MEDIUM] CWE-264 CVE-2013-4152: The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource
nvd
CVE-2011-2894MEDIUMCVSS 6.8≥ 3.0.0, ≤ 3.0.52011-10-04
CVE-2011-2894 [MEDIUM] CWE-502 CVE-2011-2894: Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, a
Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) ac
nvd
← Previous3 / 3