CVE-2010-1622
21.06.2010, 16:30
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
Vendor | Product | Version |
---|---|---|
oracle | fusion_middleware | 7.6.2 |
oracle | fusion_middleware | 11.1.1.6.1 |
oracle | fusion_middleware | 11.1.1.8.0 |
springsource | spring_framework | 2.5.0 |
springsource | spring_framework | 2.5.1 |
springsource | spring_framework | 2.5.2 |
springsource | spring_framework | 2.5.3 |
springsource | spring_framework | 2.5.4 |
springsource | spring_framework | 2.5.5 |
springsource | spring_framework | 2.5.6 |
springsource | spring_framework | 2.5.7 |
springsource | spring_framework | 3.0.0 |
springsource | spring_framework | 3.0.1 |
springsource | spring_framework | 3.0.2 |
𝑥
= Vulnerable software versions
References