CVE-2019-3773: Broadcom Spring Web Services
Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Affected products
- Broadcom Spring Web Services: up to and including 2.4.3; from 3.0.0, up to and including 3.0.4
- Oracle Financial Services Analytical Applications Infrastructure: from 8.0.6, up to and including 8.1.0
- Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
Published 2019-01-18. Last modified 2026-09-04.