← Back

Spring Web Services

spring_web_services

Vendor: Pivotal Software • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Broadcom
OraclePivotal Software
4Financial Services Analytical Applications Infrastructure
Flexcube Private BankingSpring Web Services+1 more
Sep 4, 2026
Jan 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.