Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
2019-01-18T22:29:00.973
2024-11-21T04:42:29.987
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | spring_integration | ≤ 4.3.18 | Yes |
Application | vmware | spring_integration | ≤ 5.0.10 | Yes |
Application | vmware | spring_integration | ≤ 5.1.1 | Yes |
Application | oracle | retail_customer_management_and_segmentation_foundation | 16.0 | Yes |
Application | oracle | retail_customer_management_and_segmentation_foundation | 17.0 | Yes |
Application | oracle | retail_customer_management_and_segmentation_foundation | 18.0 | Yes |