← Back

Spring Web Services

spring_web_services

Vendor: Pivotal Software • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Oracle
Pivotal Software
3Financial Services Analytical Applications Infrastructure
Flexcube Private BankingSpring Web Services
Jun 17, 2026
Jan 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.