Description
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Remediation
References
https://pivotal.io/security/cve-2019-3773
https://security.netapp.com/advisory/ntap-20231227-0011/
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpujan2021.html
Related Vulnerabilities
CVE-2022-32287 Vulnerability in maven package org.apache.uima:uimaj-core
CVE-2022-34112 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2022-39381 Vulnerability in npm package hummus
CVE-2017-2654 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2023-42795 Vulnerability in maven package org.apache.tomcat:tomcat-catalina