Skip to main content

CVE-2013-4152

6.8
CVSS v2.0 Base Score
67.95%
MEDIUM RiskEPSS (99th percentile)

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.

Published: 1/23/2014
Modified: 4/29/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

67.95%MEDIUM Exploitation Risk
99th percentile

This vulnerability has a 67.95% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

CWE Classification

Related Vulnerabilities