VulnerabilityModified
CVE-2014-0225
This enabled an XXE attack.
HIGH 8.8EPSS 1.70%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- pivotal software/spring framework · vmware/spring framework
- Source
- security_alert@emc.com
References
- https://pivotal.io/security/cve-2014-0225Vendor Advisory
- https://pivotal.io/security/cve-2014-0225Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.