Springsource maintains a modestly represented portfolio of Java application frameworks, servers, and management tools that sit in the middleware and application-runtime layer of enterprise deployments. The vendor's vulnerability profile concentrates in the Spring Framework and its associated server and management products, with recurring weaknesses centered on web-tier input handling and code generation, including cross-site scripting, cross-site request forgery, and code injection. Vulnerabilities affecting this vendor frequently acquire public exploit code, underscoring the accessibility and appeal of these widely integrated components; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Springsource over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0054MEDIUM The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote atta | Apr 17, 2014 | 6.8 | 73 | NO | NO |
CVE-2010-1622MEDIUM SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request contai | Jun 21, 2010 | 6.0 | 61 | NO | YES |
CVE-2011-2730HIGH VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twi | Dec 5, 2012 | 7.5 | 30 | NO | NO |
CVE-2013-4152MEDIUM The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers t | Jan 23, 2014 | 6.8 | 29 | NO | NO |
CVE-2009-2907MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR4, Hyperic HQ Open Source befo | Mar 24, 2010 | 4.3 | 25 | NO | YES |
CVE-2013-7315MEDIUM The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-depende | Jan 23, 2014 | 6.8 | 23 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1 | Oct 13, 2009 | 3.5 | 22 | NO | YES |
CVE-2012-1833MEDIUM VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions an | Sep 28, 2012 | 5.0 | 19 | NO | NO |
CVE-2009-2897MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface in SpringSource Hyperic HQ 3.2.x before | Oct 13, 2009 | 4.3 | 16 | NO | NO |
CVE-2009-1190MEDIUM Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Fr | Apr 27, 2009 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Springsource.
Media articles that mention a CVE ID that affects a product developed by Springsource — matched by CVE ID, not by vendor name.