Broadcom
Broadcom Spring WEB Services: vulnerabilidades y CVE
Broadcom Spring WEB Services tiene 8 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses7
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41000 | Baja (3.7) | 0.26% | — | 11 jun 2026 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps,… |
| CVE-2026-40999 | Alta (8.6) | 0.43% | — | 11 jun 2026 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request… |
| CVE-2026-40998 | Alta (8.2) | 0.39% | — | 11 jun 2026 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's… |
| CVE-2026-40997 | Media (5.3) | 0.46% | — | 11 jun 2026 | Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes,… |
| CVE-2026-40996 | Media (4.8) | 0.15% | — | 11 jun 2026 | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5… |
| CVE-2026-40995 | Media (5.4) | 0.18% | — | 11 jun 2026 | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled,… |
| CVE-2026-40994 | Alta (8.2) | 0.34% | — | 11 jun 2026 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network… |
| CVE-2019-3773 | Crítica (9.8) | 4.1% | — | 18 ene 2019 | Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. |
Otros productos de Broadcom
Fabric Operating System · 95Brocade Sannav · 54Tcpreplay · 52Brightstor Arcserve Backup · 41Brocade Fabric Operating System Firmware · 26Rabbitmq Server · 25Raid Controller WEB Interface · 22Sannav · 20Brightstor Enterprise Backup · 19Advanced Secure Gateway · 16Business Protection Suite · 16Etrust Antivirus · 16