springsource kayıtları
springsource üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %60
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-16 Configuration1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-399 Resource Management Errors1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2014-0054İstismar yok | The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entspringsource · spring framework · CWE-352 | Orta6,8 | — | %91,4 | 17 Nis 2014 |
40Planlayın | CVE-2010-1622Kavram kanıtı | SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute aspringsource · spring framework · CWE-94 | Orta6,0 | — | %52,0 | 21 Haz 2010 |
35İzleyin | CVE-2013-4152İstismar yok | The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, whspringsource · spring framework · CWE-264 | Orta6,8 | — | %25,5 | 23 Oca 2014 |
34İzleyin | CVE-2011-2730İstismar yok | VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (Espringsource · spring framework · CWE-16 | Yüksek7,5 | — | %11,8 | 5 Ara 2012 |
29İzleyin | CVE-2013-7315İstismar yok | The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInspringsource · spring framework · CWE-264 | Orta6,8 | — | %5,1 | 23 Oca 2014 |
21İzleyin | CVE-2009-1190İstismar yok | Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used wsun · jdk · CWE-399 | Orta5,0 | — | %2,8 | 27 Nis 2009 |
20İzleyin | CVE-2012-1833İstismar yok | VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers tspringsource · grails · CWE-264 | Orta5,0 | — | %1,4 | 28 Eyl 2012 |
18İzleyin | CVE-2009-2897İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface springsource · application management suite · CWE-79 | Orta4,3 | — | %2,4 | 13 Eki 2009 |
17İzleyin | CVE-2009-2907Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) beforspringsource · application management suite · CWE-79 | Orta4,3 | — | %1,2 | 24 Mar 2010 |
15İzleyin | CVE-2009-2898Kavram kanıtı | Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.springsource · application management suite · CWE-79 | Düşük3,5 | — | %1,8 | 13 Eki 2009 |
- CVE-2014-005454Planlayın
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external ent
OrtaCVSS 6,8İstismar yokEPSS %91springsource · spring framework17 Nis 2014
- CVE-2010-162240Planlayın
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute a
OrtaCVSS 6,0Kavram kanıtıEPSS %52springsource · spring framework21 Haz 2010
- CVE-2013-415235İzleyin
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, wh
OrtaCVSS 6,8İstismar yokEPSS %26springsource · spring framework23 Oca 2014
- CVE-2011-273034İzleyin
VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (E
YüksekCVSS 7,5İstismar yokEPSS %12springsource · spring framework5 Ara 2012
- CVE-2013-731529İzleyin
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLIn
OrtaCVSS 6,8İstismar yokEPSS %5springsource · spring framework23 Oca 2014
- CVE-2009-119021İzleyin
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used w
OrtaCVSS 5,0İstismar yokEPSS %3sun · jdk27 Nis 2009
- CVE-2012-183320İzleyin
VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers t
OrtaCVSS 5,0İstismar yokEPSS %1springsource · grails28 Eyl 2012
- CVE-2009-289718İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface
OrtaCVSS 4,3İstismar yokEPSS %2springsource · application management suite13 Eki 2009
- CVE-2009-290717İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) befor
OrtaCVSS 4,3Kavram kanıtıEPSS %1springsource · application management suite24 Mar 2010
- CVE-2009-289815İzleyin
Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.
DüşükCVSS 3,5Kavram kanıtıEPSS %2springsource · application management suite13 Eki 2009