CVE-2014-0225

high
Published 2017-05-25 · Modified 2024-02-28
CVSS v3
8.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2
6.8
VIR risk
8.8

Description

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-0225

vendor Authored 2026-05-27

Vendor advisory: security_alert@emc.com — https://pivotal.io/security/cve-2014-0225

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.0.6.RELEASE-14
debian debianbullseyefixed3.0.6.RELEASE-14
debian debianforkyfixed3.0.6.RELEASE-14
debian debiansidfixed3.0.6.RELEASE-14
debian debiantrixiefixed3.0.6.RELEASE-14

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.springframework:spring-webmvc>=4.0.0,<4.0.54.0.5
java Mavenorg.springframework:spring-webmvc>=3.0.0,<3.2.83.2.8

Application impact

VendorProductVersionsFixed
pivotal_softwarespring_framework3.0.0
pivotal_softwarespring_framework3.1.0
pivotal_softwarespring_framework3.2.0
pivotal_softwarespring_framework4.0.0
vmwarespring_framework3.0.1
vmwarespring_framework3.0.2
vmwarespring_framework3.0.3
vmwarespring_framework3.0.4
vmwarespring_framework3.0.5
vmwarespring_framework3.0.6
vmwarespring_framework3.0.7
vmwarespring_framework3.1.0
vmwarespring_framework3.1.1
vmwarespring_framework3.1.2
vmwarespring_framework3.1.3
vmwarespring_framework3.1.4
vmwarespring_framework3.2.0
vmwarespring_framework3.2.1
vmwarespring_framework3.2.2
vmwarespring_framework3.2.3
vmwarespring_framework3.2.4
vmwarespring_framework3.2.5
vmwarespring_framework3.2.6
vmwarespring_framework3.2.7
vmwarespring_framework3.2.8
vmwarespring_framework4.0.0
vmwarespring_framework4.0.1
vmwarespring_framework4.0.2
vmwarespring_framework4.0.3
vmwarespring_framework4.0.4

References

CWEs

CWE-611

Verify integrity in audit chain (admin only). AS-IS.