5.5
CVSSv3

CVE-2015-3192

Published: 12/07/2016 Updated: 11/04/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Pivotal Spring Framework prior to 3.2.14 and 4.x prior to 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote malicious users to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware spring framework 3.2.13

vmware spring framework 3.2.5

vmware spring framework 3.2.4

vmware spring framework 3.2.7

vmware spring framework 3.2.6

vmware spring framework 3.2.9

vmware spring framework 3.2.8

vmware spring framework 3.2.1

pivotal software spring framework 3.2.0

vmware spring framework 3.2.12

vmware spring framework 3.2.11

vmware spring framework 3.2.10

vmware spring framework 3.2.3

vmware spring framework 3.2.2

fedoraproject fedora 21

fedoraproject fedora 22

pivotal software spring framework 4.1.0

vmware spring framework 4.1.2

vmware spring framework 4.1.1

vmware spring framework 4.1.4

vmware spring framework 4.1.3

vmware spring framework 4.1.6

vmware spring framework 4.1.5

Vendor Advisories

Debian Bug report logs - #796137 CVE-2015-3192 Package: src:libspring-java; Maintainer for src:libspring-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 19 Aug 2015 19:09:02 UTC Severity: important Tags: security Found in ver ...
A denial of service flaw was found in the way Spring processes inline DTD declarations A remote attacker could submit a specially crafted XML file that would cause out-of-memory errors when parsed ...

Github Repositories

Vulnerability of Spring to XML Bomb Referencing CVE-2015-3192: Pivotal CVE SourceClear CVE Spring Bug Report Objective of this project: Determine the vulnerable methods causing this bug Proof of concept of the vulnerability Plan: Have a simple hello world Spring application Accept XML payload Send XML bomb Demonstrate vulnerability Steps Run the sample app via mvn jetty: