Pivotal Spring Integration CVE-2019-3772 XML External Entity Injection Vulnerability
BID:106749
CVE-2019-3772 |Info
Pivotal Spring Integration CVE-2019-3772 XML External Entity Injection Vulnerability
| Bugtraq ID: | 106749 |
| Class: | Unknown |
| CVE: |
CVE-2019-3772 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2019 12:00AM |
| Updated: | Apr 17 2019 07:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Pivotal Spring Integration 5.1.1 Pivotal Spring Integration 5.0.10 Pivotal Spring Integration 4.3.18 Oracle Retail Customer Management and Segmentation Foundation 18.0 Oracle Retail Customer Management and Segmentation Foundation 17.0 Oracle Retail Customer Management and Segmentation Foundation 16.0 |
| Not Vulnerable: |
Pivotal Spring Integration 5.1.2 Pivotal Spring Integration 5.0.11 Pivotal Spring Integration 4.3.19 |
Discussion
Pivotal Spring Integration CVE-2019-3772 XML External Entity Injection Vulnerability
Pivotal Spring Integration is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to gain access to sensitive information or cause denial-of-service conditions.
Spring Integration versions 5.1.1, 5.0.10, and 4.3.18; other versions may also be vulnerable.
Pivotal Spring Integration is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to gain access to sensitive information or cause denial-of-service conditions.
Spring Integration versions 5.1.1, 5.0.10, and 4.3.18; other versions may also be vulnerable.
Exploit / POC
Pivotal Spring Integration CVE-2019-3772 XML External Entity Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Pivotal Spring Integration CVE-2019-3772 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Pivotal Spring Integration CVE-2019-3772 XML External Entity Injection Vulnerability
References:
References:
- Pivotal Homepage (Pivotal)
- CVE-2019-3772: XML External Entity Injection (XXE) (Pivotal)
- Oracle Critical Patch Update Advisory - April 2019 (Oracle)