← Browse

CVE-2019-3773

Medium

Elevated severity or exploit probability.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
4.1%
90.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-611
Published 2019-01-18 · modified 2026-09-04

Description

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Affected

broadcom oracle

References

Official: NVD · CVE.org