XML External Entity injection in Spring Web Services - CVE-2019-3773
Published: January 24, 2019
Vulnerability identifier: #VU17185
CSH Severity: Low
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3773
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to conduct XXE-attack.
The vulnerability exists due to improper handling of XML External Entities (XXEs) when parsing an XML file. A remote attacker can supply a specially crafted input and obtain potentially sensitive information or cause the service to crash
Affected software
Spring Web Services
Oracle Financial Services Analytical Applications Infrastructure
Oracle FLEXCUBE Private Banking
Oracle Financial Services Analytical Applications Infrastructure
Oracle FLEXCUBE Private Banking
How to mitigate CVE-2019-3773
The vulnerability has been fixed in the versions 2.4.4, 3.0.6.
Spring Web Services - addressed in versions 2.4.4, 3.0.6