← Back

CVE-2014-0225

nvd nist
Published: May 25, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Affected (34)

Spring Framework
1 product
Spring Framework
Configuration A
34 vulnerable
Vulnerable SoftwareAffected Versions
Pivotal Software
Version 3.0.0
Version 3.1.0
Version 3.2.0
Version 4.0.0
Vmware
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.0.6
Version 3.0.7
Version 3.1.0 rc1
Version 3.1.0 rc2
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.2.0 rc1
Version 3.2.0 rc2-a
Version 3.2.0 rc2
Version 3.2.1
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.2.8
Version 4.0.0 rc1
Version 4.0.0 rc2
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4

References (2)

Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.