Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-22968


In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.


Published

2022-04-14T21:15:08.643

Last Modified

2024-11-21T06:47:42.537

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-178

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware spring_framework < 5.2.0 Yes
Application vmware spring_framework ≤ 5.2.20 Yes
Application vmware spring_framework ≤ 5.3.18 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp cloud_secure_agent - Yes
Application netapp metrocluster_tiebreaker - Yes
Application netapp snap_creator_framework - Yes
Application netapp snapmanager - Yes
Application netapp snapmanager - Yes
Application oracle mysql_enterprise_monitor ≤ 8.0.29 Yes

References