CVE-2020-5421

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/09/2020
Last modified:
07/11/2023

Description

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* 4.3.29 (excluding)
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.19 (excluding)
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* 5.1.0 (including) 5.1.18 (excluding)
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* 5.2.0 (including) 5.2.9 (excluding)
cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_brm:11.3.0.9:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_brm:12.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_design_studio:7.3.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_design_studio:7.3.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_design_studio:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:* 8.2.1 (including) 8.2.2.1 (including)
cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:endeca_information_discovery_integrator:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_data_quality:12.2.1.3.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools