Search/CVE-2014-3625
CVE

CVE-2014-3625

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVSS v3.1
EPSS
10.3%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 7, 2026
0.27pp
10.1% → 10.3% over 2 tracked changes
Connections
3 relationships
Timeline
disclosure → media coverage
Nov 20, 2014
Disclosure — published as a CVE record. · last revised by NVD May 6, 2026
Public PoC (2)
Unverified third-party code — review before executing.