CVE-2013-4152

Description

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
89.008

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2013-4152,CVE-2013-7315 are fixed in spring-oxm 3.2.4Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.5Windows
Multiple Vulnerabilities are affected in IBM Security Verify Directory Integrator 7.2.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.4Windows
Vulnerabilities CVE-2013-4152,CVE-2013-7315 are fixed in spring-oxm for Linux 3.2.4Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234