In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N)
- CVSS 3.0 Base Score: 8.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libspring-java | Jul 30, 2024 | Sep 19, 2020 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 32052267 for version 10.3.6.0.0.Apply the Patch Set Update (PSU) 32052261 for version 12.1.3.0.0.Apply the Patch Set Update (PSU) 32253037 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 32247800 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 32300397 for version 12.2.1.3.0. | Jan 19, 2021 | Sep 19, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub