6.8
CVSSv2

CVE-2014-0225

Published: 25/05/2017 Updated: 11/04/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware spring framework 3.1.3

vmware spring framework 3.1.4

pivotal software spring framework 3.0.0

vmware spring framework 3.0.1

vmware spring framework 3.2.1

pivotal software spring framework 3.2.0

pivotal software spring framework 4.0.0

vmware spring framework 4.0.1

vmware spring framework 3.1.0

vmware spring framework 4.0.0

vmware spring framework 3.1.1

vmware spring framework 3.0.3

vmware spring framework 3.0.5

vmware spring framework 3.2.4

vmware spring framework 3.2.2

vmware spring framework 4.0.2

vmware spring framework 4.0.4

vmware spring framework 3.2.0

vmware spring framework 3.0.7

vmware spring framework 3.2.8

vmware spring framework 3.2.6

vmware spring framework 3.2.7

pivotal software spring framework 3.1.0

vmware spring framework 3.1.2

vmware spring framework 3.0.2

vmware spring framework 3.0.4

vmware spring framework 3.0.6

vmware spring framework 3.2.5

vmware spring framework 3.2.3

vmware spring framework 4.0.3

Vendor Advisories

Debian Bug report logs - #760733 CVE-2014-3578: directory traversal Package: src:libspring-java; Maintainer for src:libspring-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Yves-Alexis Perez <corsac@debianorg> Date: Sun, 7 Sep 2014 11:33:05 UTC Severity: important Tags: ...
Debian Bug report logs - #753470 libspring-java: CVE-2014-0225 Package: libspring-java; Maintainer for libspring-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 2 Jul 2014 08:54:02 UTC Severity: grave Tags: patch, security F ...
It was found that the Spring Framework did not, by default, disable the resolution of URI references in a DTD declaration when processing user-provided XML documents By observing differences in response times, an attacker could identify valid IP addresses on the internal network with functioning web servers ...