Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-5421


In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.


Published

2020-09-19T04:15:11.527

Last Modified

2024-11-21T05:34:08.303

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:H/Au:S/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware spring_framework < 4.3.29 Yes
Application vmware spring_framework < 5.0.19 Yes
Application vmware spring_framework < 5.1.18 Yes
Application vmware spring_framework < 5.2.9 Yes
Application oracle commerce_guided_search 11.3.2 Yes
Application oracle communications_brm 11.3.0.9 Yes
Application oracle communications_brm 12.0.0.3 Yes
Application oracle communications_design_studio 7.3.4 Yes
Application oracle communications_design_studio 7.3.5 Yes
Application oracle communications_design_studio 7.4.0 Yes
Application oracle communications_session_report_manager ≤ 8.2.2.1 Yes
Application oracle communications_unified_inventory_management 7.3.4 Yes
Application oracle communications_unified_inventory_management 7.3.5 Yes
Application oracle endeca_information_discovery_integrator 3.2.0 Yes
Application oracle enterprise_data_quality 12.2.1.3.0 Yes
Application oracle enterprise_data_quality 12.2.1.4.0 Yes
Application oracle financial_services_analytical_applications_infrastructure ≤ 8.1.0 Yes
Application oracle flexcube_private_banking 12.0.0 Yes
Application oracle flexcube_private_banking 12.1.0 Yes
Application oracle fusion_middleware 12.2.1.3.0 Yes
Application oracle fusion_middleware 12.2.1.4.0 Yes
Application oracle goldengate_application_adapters 19.1.0.0.0 Yes
Application oracle healthcare_master_person_index 4.0.2.5 Yes
Application oracle hyperion_infrastructure_technology 11.1.2.4 Yes
Application oracle insurance_policy_administration ≤ 11.3.0 Yes
Application oracle insurance_policy_administration 10.2 Yes
Application oracle insurance_policy_administration 10.2.4 Yes
Application oracle insurance_policy_administration 11.0.2 Yes
Application oracle insurance_rules_palette ≤ 11.3.0 Yes
Application oracle insurance_rules_palette 10.2.0 Yes
Application oracle insurance_rules_palette 10.2.4 Yes
Application oracle insurance_rules_palette 11.0.2 Yes
Application oracle mysql_enterprise_monitor ≤ 8.0.22 Yes
Application oracle mysql_enterprise_monitor 8.0.23 Yes
Application oracle primavera_gateway ≤ 16.2.11 Yes
Application oracle primavera_gateway ≤ 17.12.9 Yes
Application oracle primavera_gateway ≤ 18.8.10 Yes
Application oracle primavera_gateway ≤ 19.12.10 Yes
Application oracle primavera_p6_enterprise_project_portfolio_management ≤ 16.2.20 Yes
Application oracle primavera_p6_enterprise_project_portfolio_management ≤ 17.12.19 Yes
Application oracle primavera_p6_enterprise_project_portfolio_management ≤ 18.8.21 Yes
Application oracle primavera_p6_enterprise_project_portfolio_management ≤ 19.12.10 Yes
Application oracle retail_assortment_planning 16.0.3.0 Yes
Application oracle retail_bulk_data_integration 16.0.3.0 Yes
Application oracle retail_customer_engagement ≤ 19.0 Yes
Application oracle retail_customer_management_and_segmentation_foundation ≤ 19.0 Yes
Application oracle retail_financial_integration 14.1.3 Yes
Application oracle retail_financial_integration 15.0.3 Yes
Application oracle retail_financial_integration 16.0.3 Yes
Application oracle retail_integration_bus 14.1.3 Yes
Application oracle retail_integration_bus 15.0.3 Yes
Application oracle retail_integration_bus 16.0.3 Yes
Application oracle retail_invoice_matching 14.0 Yes
Application oracle retail_invoice_matching 14.1 Yes
Application oracle retail_merchandising_system 16.0.3 Yes
Application oracle retail_order_broker 15.0 Yes
Application oracle retail_order_broker 16.0 Yes
Application oracle retail_predictive_application_server 14.1 Yes
Application oracle retail_returns_management 14.1 Yes
Application oracle retail_service_backbone 14.1.3 Yes
Application oracle retail_service_backbone 15.0.3 Yes
Application oracle retail_service_backbone 16.0.3 Yes
Application oracle retail_xstore_point_of_service 15.0.4 Yes
Application oracle retail_xstore_point_of_service 16.0.6 Yes
Application oracle retail_xstore_point_of_service 17.0.4 Yes
Application oracle retail_xstore_point_of_service 18.0.3 Yes
Application oracle retail_xstore_point_of_service 19.0.2 Yes
Application oracle storagetek_acsls 8.5.1 Yes
Application oracle storagetek_tape_analytics_sw_tool 2.3 Yes
Application oracle weblogic_server 10.3.6.0.0 Yes
Application oracle weblogic_server 12.1.3.0.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Application oracle weblogic_server 14.1.1.0.0 Yes
Application netapp oncommand_insight - Yes
Application netapp snap_creator_framework - Yes
Application netapp snapcenter - Yes

References