In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
2022-05-12T20:15:15.110
2024-11-21T06:47:43.027
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | spring_framework | ≤ 5.2.21 | Yes |
Application | vmware | spring_framework | ≤ 5.3.19 | Yes |
Application | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 | Yes |
Application | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 | Yes |
Application | netapp | cloud_secure_agent | - | Yes |
Application | netapp | oncommand_insight | - | Yes |