8.8

CVE-2014-0225

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareSpring Framework Version3.0.1
VMwareSpring Framework Version3.0.2
VMwareSpring Framework Version3.0.3
VMwareSpring Framework Version3.0.4
VMwareSpring Framework Version3.0.5
VMwareSpring Framework Version3.0.6
VMwareSpring Framework Version3.0.7
VMwareSpring Framework Version3.1.0 Updaterc1
VMwareSpring Framework Version3.1.0 Updaterc2
VMwareSpring Framework Version3.1.1
VMwareSpring Framework Version3.1.2
VMwareSpring Framework Version3.1.3
VMwareSpring Framework Version3.1.4
VMwareSpring Framework Version3.2.0 Updaterc1
VMwareSpring Framework Version3.2.0 Updaterc2
VMwareSpring Framework Version3.2.0 Updaterc2-a
VMwareSpring Framework Version3.2.1
VMwareSpring Framework Version3.2.2
VMwareSpring Framework Version3.2.3
VMwareSpring Framework Version3.2.4
VMwareSpring Framework Version3.2.5
VMwareSpring Framework Version3.2.6
VMwareSpring Framework Version3.2.7
VMwareSpring Framework Version3.2.8
VMwareSpring Framework Version4.0.0 Updaterc1
VMwareSpring Framework Version4.0.0 Updaterc2
VMwareSpring Framework Version4.0.1
VMwareSpring Framework Version4.0.2
VMwareSpring Framework Version4.0.3
VMwareSpring Framework Version4.0.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.459
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.