CVE-2019-3774

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 86.56%
Affected Products (NVD)
VendorProductVersion
broadcomspring_batch
𝑥
≤ 3.0.9
broadcomspring_batch
4.0.0 ≤
𝑥
≤ 4.0.1
broadcomspring_batch
4.1.0
𝑥
= Vulnerable software versions
References