Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOracle Financial Services Analytical Applications Infrastructure
APPOracle8.0.6 – 8.1.0Oracle Flexcube Private Banking
APPOracle12.0.012.1.0Pivotal Software Spring Web Services
APPPivotal Software≤ 2.4.33.0.0 – 3.0.4
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XXE
References
Related vulnerabilities
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓same product
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
CVE-2025-53037CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia w Oracle Financial Services Analytical Applications Infrastructure
CVE-2021-26291CRITICAL9.1PL ✓same product
Apache Maven: podążanie za niezaufanymi repozytoriami HTTP (MitM)
CVE-2020-11998CRITICAL9.8PL ✓same product
Apache ActiveMQ — RCE przez błędną konfigurację JMX RMIConnectorServer