Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
2016-07-12T19:59:00.240
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 5.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pivotal_software | spring_framework | 3.2.0 | Yes |
Application | vmware | spring_framework | 3.2.1 | Yes |
Application | vmware | spring_framework | 3.2.2 | Yes |
Application | vmware | spring_framework | 3.2.3 | Yes |
Application | vmware | spring_framework | 3.2.4 | Yes |
Application | vmware | spring_framework | 3.2.5 | Yes |
Application | vmware | spring_framework | 3.2.6 | Yes |
Application | vmware | spring_framework | 3.2.7 | Yes |
Application | vmware | spring_framework | 3.2.8 | Yes |
Application | vmware | spring_framework | 3.2.9 | Yes |
Application | vmware | spring_framework | 3.2.10 | Yes |
Application | vmware | spring_framework | 3.2.11 | Yes |
Application | vmware | spring_framework | 3.2.12 | Yes |
Application | vmware | spring_framework | 3.2.13 | Yes |
Operating System | fedoraproject | fedora | 21 | Yes |
Operating System | fedoraproject | fedora | 22 | Yes |
Application | pivotal_software | spring_framework | 4.1.0 | Yes |
Application | vmware | spring_framework | 4.1.1 | Yes |
Application | vmware | spring_framework | 4.1.2 | Yes |
Application | vmware | spring_framework | 4.1.3 | Yes |
Application | vmware | spring_framework | 4.1.4 | Yes |
Application | vmware | spring_framework | 4.1.5 | Yes |
Application | vmware | spring_framework | 4.1.6 | Yes |