VMware

Spring Framework

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.55%
  • Veröffentlicht 17.04.2014 14:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct ...

  • EPSS 38.73%
  • Veröffentlicht 26.01.2014 16:58:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CS...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 23.01.2014 21:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and c...

Exploit
  • EPSS 72.32%
  • Veröffentlicht 23.01.2014 21:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF at...

  • EPSS 2%
  • Veröffentlicht 04.10.2011 10:55:09
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and exec...