In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
2022-05-12T20:15:15.037
2024-11-21T06:47:42.860
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:N/A:P
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | spring_framework | ≤ 5.2.21 | Yes |
Application | vmware | spring_framework | ≤ 5.3.19 | Yes |
Application | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 | Yes |
Application | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | brocade_san_navigator | - | Yes |
Application | netapp | cloud_secure_agent | - | Yes |
Application | netapp | oncommand_insight | - | Yes |