{
  "@id": "urn:uuid:c748f3dc-3c8c-48bd-8b70-3847d59ca124",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-28T14:23:00.070779+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-28T14:23:00.070779+00:00",
      "status_notes": "Vulnerability CVE-2019-3773 does not affect version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core. CVE-2019-3773 (XXE vulnerability) is not present in Spring Web Services v2.4.5.RELEASE. The upstream vendor (Pivotal/Spring) fixed this vulnerability in commit d1c87ab466df (SWS-1049) on 2018-12-07, authored by Greg Turnquist. This fix was included in the v2.4.5.RELEASE tag before TuxCare onboarded this version. The fix introduces secure utility wrapper classes (DocumentBuilderFactoryUtils, XMLInputFactoryUtils, TransformerFactoryUtils) that replace direct XML parser factory instantiation and automatically configure XXE protections by disabling external entity processing, DTD support, and external schema access.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2019-3773"
      },
      "impact_statement": "CVE-2019-3773 (XXE vulnerability) is not present in Spring Web Services v2.4.5.RELEASE. The upstream vendor (Pivotal/Spring) fixed this vulnerability in commit d1c87ab466df (SWS-1049) on 2018-12-07, authored by Greg Turnquist. This fix was included in the v2.4.5.RELEASE tag before TuxCare onboarded this version. The fix introduces secure utility wrapper classes (DocumentBuilderFactoryUtils, XMLInputFactoryUtils, TransformerFactoryUtils) that replace direct XML parser factory instantiation and automatically configure XXE protections by disabling external entity processing, DTD support, and external schema access."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40994 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core.",
      "vulnerability": {
        "name": "CVE-2026-40994"
      },
      "action_statement": "Vulnerability CVE-2026-40994 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40995 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core.",
      "vulnerability": {
        "name": "CVE-2026-40995"
      },
      "action_statement": "Vulnerability CVE-2026-40995 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40996 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core.",
      "vulnerability": {
        "name": "CVE-2026-40996"
      },
      "action_statement": "Vulnerability CVE-2026-40996 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40997 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core.",
      "vulnerability": {
        "name": "CVE-2026-40997"
      },
      "action_statement": "Vulnerability CVE-2026-40997 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40998 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core.",
      "vulnerability": {
        "name": "CVE-2026-40998"
      },
      "action_statement": "Vulnerability CVE-2026-40998 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40999 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core.",
      "vulnerability": {
        "name": "CVE-2026-40999"
      },
      "action_statement": "Vulnerability CVE-2026-40999 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.ws/spring-ws-core@2.4.5.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41000 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core.",
      "vulnerability": {
        "name": "CVE-2026-41000"
      },
      "action_statement": "Vulnerability CVE-2026-41000 affects version 2.4.5.RELEASE-tuxcare.1 of org.springframework.ws:spring-ws-core."
    }
  ]
}
