6.8

CVE-2013-7315

Exploit

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152.  NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

Data is provided by the National Vulnerability Database (NVD)
SpringsourceSpring Framework Version3.0.0
SpringsourceSpring Framework Version3.0.0 Updatem1
SpringsourceSpring Framework Version3.0.0 Updatem2
SpringsourceSpring Framework Version3.0.0 Updatem3
SpringsourceSpring Framework Version3.0.0 Updatem4
SpringsourceSpring Framework Version3.0.0 Updaterc1
SpringsourceSpring Framework Version3.0.0 Updaterc2
SpringsourceSpring Framework Version3.0.0 Updaterc3
SpringsourceSpring Framework Version3.0.0.m1
SpringsourceSpring Framework Version3.0.0.m2
SpringsourceSpring Framework Version3.0.1
SpringsourceSpring Framework Version3.0.2
SpringsourceSpring Framework Version3.0.3
SpringsourceSpring Framework Version3.0.4
SpringsourceSpring Framework Version3.0.5
VMwareSpring Framework Version <= 3.2.3
VMwareSpring Framework Version3.0.6
VMwareSpring Framework Version3.0.7
VMwareSpring Framework Version3.1.0
VMwareSpring Framework Version3.1.1
VMwareSpring Framework Version3.1.2
VMwareSpring Framework Version3.1.3
VMwareSpring Framework Version3.1.4
VMwareSpring Framework Version3.2.0
VMwareSpring Framework Version3.2.1
VMwareSpring Framework Version3.2.2
VMwareSpring Framework Version4.0.0 Updatemilestone1
VMwareSpring Framework Version4.0.0 Updatemilestone2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.52% 0.659
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P