Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HBroadcom Spring Batch
APPBroadcom4.1.0≤ 3.0.94.0.0 – 4.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XXE
References
Related vulnerabilities
CVE-2020-5411HIGH8.1same product
When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to...
CVE-2026-47875MEDIUM5.6same product
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable ...
CVE-2026-47881MEDIUM5.9same product
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines —...
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same vendor
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2018-1273CRITICAL9.8⚠ KEVPL ✓same vendor
RCE w Spring Data Commons — podatność property bindera