CVE-2019-3772
18.01.2019, 22:29
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | spring_integration | 𝑥 ≤ 4.3.18 |
vmware | spring_integration | 5.0.0 ≤ 𝑥 ≤ 5.0.10 |
vmware | spring_integration | 5.1.0 ≤ 𝑥 ≤ 5.1.1 |
oracle | retail_customer_management_and_segmentation_foundation | 16.0 |
oracle | retail_customer_management_and_segmentation_foundation | 17.0 |
oracle | retail_customer_management_and_segmentation_foundation | 18.0 |
𝑥
= Vulnerable software versions
References