CVE-2019-3773EPSS p90.5%
CVE-2019-3773CVE-2019-3773
broadcom / spring_web_services
Description
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.11% probability of exploitation · percentile 90.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-04 |