6.8
CVSSv2

CVE-2013-7315

Published: 23/01/2014 Updated: 11/04/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Spring MVC in Spring Framework prior to 3.2.4 and 4.0.0.M1 up to and including 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent malicious users to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware spring framework 3.1.4

vmware spring framework 3.1.3

vmware spring framework 4.0.0

springsource spring framework 3.0.5

springsource spring framework 3.0.0

vmware spring framework

vmware spring framework 3.2.2

vmware spring framework 3.1.0

vmware spring framework 3.0.7

springsource spring framework 3.0.2

springsource spring framework 3.0.1

springsource spring framework 3.0.0.m2

vmware spring framework 3.2.1

vmware spring framework 3.2.0

vmware spring framework 3.0.6

springsource spring framework 3.0.0.m1

vmware spring framework 3.1.2

vmware spring framework 3.1.1

springsource spring framework 3.0.4

springsource spring framework 3.0.3

Vendor Advisories

The Spring MVC in Spring Framework before 324 and 400M1 through 400M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a differe ...