{"id":"CVE-2019-3773","aliases":["GHSA-8222-6fc8-mhvf"],"url":"https://o3.security/vulnerability/CVE-2019-3773","summary":"Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml","details":"Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.","published":"2019-01-18T22:29:01.020Z","modified":"2026-09-06T11:45:09.554454756Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework.ws:spring-ws","fixedVersion":"2.4.4"},{"ecosystem":"Maven","name":"org.springframework.ws:spring-ws","fixedVersion":"3.0.6"},{"ecosystem":"Maven","name":"org.springframework.ws:spring-xml","fixedVersion":"2.4.4"},{"ecosystem":"Maven","name":"org.springframework.ws:spring-xml","fixedVersion":"3.0.6"}],"fix":null,"references":[{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2019-3773"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20231227-0011/"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-3773"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8222-6fc8-mhvf"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2021.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-06T11:45:09.554454756Z"}}