CVE-2019-3773
18.01.2019, 22:29
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.Enginsight
Vendor | Product | Version |
---|---|---|
pivotal_software | spring_web_services | 𝑥 ≤ 2.4.3 |
pivotal_software | spring_web_services | 3.0.0 ≤ 𝑥 ≤ 3.0.4 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | flexcube_private_banking | 12.0.0 |
oracle | flexcube_private_banking | 12.1.0 |
𝑥
= Vulnerable software versions
References