CVE-2019-3772: Oracle Retail Customer Management And Segmentation Foundation
Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Affected products
- Oracle Retail Customer Management And Segmentation Foundation: version 16.0 only; version 17.0 only; version 18.0 only
- VMware Spring Integration: up to and including 4.3.18; from 5.0.0, up to and including 5.0.10; from 5.1.0, up to and including 5.1.1
Published 2019-01-18. Last modified 2026-06-17.