XML External Entity injection in Spring Web Services - CVE-2019-3773

 

XML External Entity injection in Spring Web Services - CVE-2019-3773

Published: January 24, 2019


Vulnerability identifier: #VU17185
CSH Severity: Low
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3773
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to conduct XXE-attack.

The vulnerability exists due to improper handling of XML External Entities (XXEs) when parsing an XML file. A remote attacker can supply a specially crafted input and obtain potentially sensitive information or cause the service to crash


Affected software

Spring Web Services
Oracle Financial Services Analytical Applications Infrastructure
Oracle FLEXCUBE Private Banking

How to mitigate CVE-2019-3773

The vulnerability has been fixed in the versions 2.4.4, 3.0.6.

Spring Web Services - addressed in versions 2.4.4, 3.0.6

External References

Related Security Bulletins