{"id":"CVE-2019-3773","title":"Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.","summary":"Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-611","CWE-611"],"vendor":"broadcom","product":"spring_web_services","affected":["spring_web_services <= 2.4.3","spring_web_services >= 3.0.0, <= 3.0.4","financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.0","flexcube_private_banking = 12.0.0","flexcube_private_banking = 12.1.0"],"published":"2019-01-18","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-3773","references":[{"url":"https://pivotal.io/security/cve-2019-3773","label":"security_alert@emc.com"},{"url":"https://security.netapp.com/advisory/ntap-20231227-0011/","label":"security_alert@emc.com"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"security_alert@emc.com"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"security_alert@emc.com"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"security_alert@emc.com"},{"url":"https://pivotal.io/security/cve-2019-3773","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20231227-0011/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0411,"epssPercentile":0.9035,"ingestedAt":"2026-09-04T14:22:24.881Z","slug":"CVE-2019-3773","body":"## Overview\n\nSpring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.\n\n## Affected\n\n- `spring_web_services <= 2.4.3`\n- `spring_web_services >= 3.0.0, <= 3.0.4`\n- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.0`\n- `flexcube_private_banking = 12.0.0`\n- `flexcube_private_banking = 12.1.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":53.9,"likelihood":0.8,"exploitation":0,"ransomware":0},"changes":[]}