SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0225

This enabled an XXE attack.

HIGH 8.8EPSS 1.70%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS 3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
1.70% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
pivotal software/spring framework · vmware/spring framework
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.